Malware

How to remove “Win32/Kryptik.ZE”?

Malware Removal

The Win32/Kryptik.ZE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ZE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Win32/Kryptik.ZE?


File Info:

name: 4843F30143210105B15C.mlw
path: /opt/CAPEv2/storage/binaries/6438f954a5b44d6978733c9c7dce9d861941956be47c0049d9aee0471014224e
crc32: 711897CC
md5: 4843f30143210105b15cd08d089b6395
sha1: 0b6c7aa8e97c782de80f4e10be50bb34fdcc7364
sha256: 6438f954a5b44d6978733c9c7dce9d861941956be47c0049d9aee0471014224e
sha512: 9e36decf394066411a8e6bf9fd8c894caf521acb83cdd773fb407e9308206efb8116d119e86774af5563a0353eb98b4cb11dbc079d7a50d82ac5eff56a87f9f1
ssdeep: 768:WBSOe5oiq9DHqcs61GTdnEQM7i+6k3RnRq1RA4D5:WBSOUo3H9s610x7M7i+RRqXA4D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160C2CFD74948D306D3DAD7FA0E898426F236020921F6F82CFE0B5E4043B75A577A865E
sha3_384: e0c466d342b70eb75eb22abe4b89fff82089a7346f01498cc4951ba42a5f8158584be23aa10a17843cf7a4921ca0bf1c
ep_bytes: 558bec83ec0c5357568d0d7881e93133
timestamp: 2009-07-20 10:59:44

Version Info:

0: [No Data]

Win32/Kryptik.ZE also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Packed.bmW@auqODKn
FireEyeGeneric.mg.4843f30143210105
McAfeeFakeAV-DA
CylanceUnsafe
VIPREGen:Packed.bmW@auqODKn
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005727771 )
K7GWTrojan ( 005727771 )
Cybereasonmalicious.143210
BitDefenderThetaAI:Packer.695906091E
CyrenW32/FakeAlert.BO.gen!Eldorado
SymantecPacked.Mystic!gen1
ESET-NOD32a variant of Win32/Kryptik.ZE
TrendMicro-HouseCallTROJ_FAKEAV.SMJO
ClamAVWin.Trojan.TDSS-1737
KasperskyPacked.Win32.TDSS.x
BitDefenderGen:Packed.bmW@auqODKn
NANO-AntivirusTrojan.Win32.TDSS.bstmko
CynetMalicious (score: 100)
AvastWin32:Alureon-CG [Rtk]
Ad-AwareGen:Packed.bmW@auqODKn
TACHYONTrojan/W32.TDSS.26624.N
EmsisoftGen:Packed.bmW@auqODKn (B)
ComodoTrojWare.Win32.Spy.Zbot.ABH@1pwavx
DrWebBackDoor.Tdss.119
ZillyaTrojan.Tdss.Win32.1520
TrendMicroTROJ_FAKEAV.SMJO
McAfee-GW-EditionBehavesLike.Win32.Packed.mc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-IV
APEXMalicious
GDataGen:Packed.bmW@auqODKn
JiangminTrojan/Tdss.ekq
WebrootW32.Alureon.Rootkit
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.29
ArcabitGen:Packed.EA7DAC
ViRobotTrojan.Win32.Tdss.26624.AR
MicrosoftTrojan:Win32/Alureon.BK
GoogleDetected
VBA32BScope.Trojan.Downloader
MAXmalware (ai score=87)
RisingTrojan.Zbot!8.1C74 (TFE:2:5RAGuSpgG2O)
YandexTrojan.TDSS!qLkkoyZtZ0I
IkarusPacker.Win32.Krap
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PackTDss.W!tr
AVGWin32:Alureon-CG [Rtk]
PandaBck/Tdss.AL
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.ZE?

Win32/Kryptik.ZE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment