Malware

What is “Win32:Kryptik-LUA [Trj]”?

Malware Removal

The Win32:Kryptik-LUA [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Kryptik-LUA [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Win32:Kryptik-LUA [Trj]?


File Info:

name: 933E6B24A3409539C2AC.mlw
path: /opt/CAPEv2/storage/binaries/b94647b169effd1d7ae2be89c52819b984535c8e7e72a539d1d737abd54f5f06
crc32: E79C7B12
md5: 933e6b24a3409539c2ac9547e19fb678
sha1: e4c44285e4f82c264c8f2dbf021362136e5e4028
sha256: b94647b169effd1d7ae2be89c52819b984535c8e7e72a539d1d737abd54f5f06
sha512: 4da82c8ddec0582cbd22e89c71d74253ac0928231d8a967b75d0458a87f1eb6c99487436f380701a2ba031358d15f2b7122088477af3613f2a7c8941e6749842
ssdeep: 3072:aU9XTpcvocFIALdm3vL5wI1G6OoBQXTmy5xEKJ9W8NR9vmwXeegZ4cphf/:R9X1qoEd2v9wI1XOoTDHER9XcTH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B704BF537AD3C9DAEC2B4E364843CAFC36517D63E562628726C1EF0FE8F22461D26611
sha3_384: dac2dfb16c79ce764df7a5afd2581b600ce0d171c240b66f8f07159ef25e834a653f67602fa2eb30c025f68609c5dd14
ep_bytes: 53515256c884000081ed82000000c745
timestamp: 2013-05-22 11:52:03

Version Info:

0: [No Data]

Win32:Kryptik-LUA [Trj] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.24
CAT-QuickHealTrojan.GenericPMF.S32679457
SkyhighBehavesLike.Win32.Dropper.ch
McAfeeDropper-FFQ!933E6B24A340
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.Mint.Zard.24
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0040f4c81 )
K7AntiVirusTrojan ( 0040f4c81 )
VirITTrojan.Win32.Generic.VVS
SymantecSMG.Heur!gen
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GUXR
APEXMalicious
TrendMicro-HouseCallPAK_Xed-21
ClamAVWin.Malware.Ulise-6840317-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.24
AvastWin32:Kryptik-LUA [Trj]
TencentTrojan.Win32.Kryptik.kbx
EmsisoftGen:Heur.Mint.Zard.24 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Mods.146
ZillyaTrojan.Kryptik.Win32.4601400
TrendMicroPAK_Xed-21
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.933e6b24a3409539
SophosTroj/Gepys-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=88)
JiangminTrojan/Generic.awsky
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/GenTroj.BW.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojanDropper:Win32/Gepys!pz
XcitiumTrojWare.Win32.Kryptik.BBSW@4xttk5
ArcabitTrojan.Mint.Zard.24
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.17GTXUI
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R635927
Acronissuspicious
VBA32Virus.Virlock.gen
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B5A3 (CLASSIC)
YandexTrojan.GenAsa!S5LTJErtm2o
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BBSW!tr
BitDefenderThetaGen:NN.ZexaF.36802.luZ@a8B0Exm
AVGWin32:Kryptik-LUA [Trj]
DeepInstinctMALICIOUS

How to remove Win32:Kryptik-LUA [Trj]?

Win32:Kryptik-LUA [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment