Malware

Win32:RPoly [Cryp] removal guide

Malware Removal

The Win32:RPoly [Cryp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:RPoly [Cryp] virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with NsPack
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics

How to determine Win32:RPoly [Cryp]?


File Info:

name: 6416F3A7312D60BF7B45.mlw
path: /opt/CAPEv2/storage/binaries/927188443e272a632cf75556664d7dd6a53954d658a863f8f18ef9090839e461
crc32: 93AAD2BD
md5: 6416f3a7312d60bf7b45ca3104b7420c
sha1: e82cb61942e41100e91765b7f6d019e151179e72
sha256: 927188443e272a632cf75556664d7dd6a53954d658a863f8f18ef9090839e461
sha512: 986369b3ac8d38f4835f2dbd4f6c9ec93555ba8c639032e0b651b58db34e58ef6ad23e9bd4bae49fdc74c807d904d494b89a9b605dbe1508b5754ef892eee6cb
ssdeep: 12288:BO3KBEBBZ4N64PVgDs4LwYtVW7gt8Gp2H:BOeEE6wgDdW7gaGp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A23523A34BA8250FD52E1CF1E95120BBDC77A18AD9BD1B02E6F647DF2944A3F6806142
sha3_384: 67f2b8f913b214b37ea5d7a729c50011a9c1ae1a23d73da095f79800f48e778cfa971131ca7d948d4a13709152d262e5
ep_bytes: 00000000000000000000000000000000
timestamp: 2007-08-19 09:01:10

Version Info:

0: [No Data]

Win32:RPoly [Cryp] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.Heur.PT.frZ@aisNjGn
FireEyeGeneric.mg.6416f3a7312d60bf
SkyhighBehavesLike.Win32.Generic.tz
ALYacGen:Trojan.Heur.PT.frZ@aisNjGn
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005257651 )
AlibabaWorm:Win32/EncPk.28b1673e
K7GWTrojan ( 005257651 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.3E9965AA1E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ZonerProbably Heur.ExeHeaderP
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Trojan.Heur.PT.frZ@aisNjGn
AvastWin32:RPoly [Cryp]
EmsisoftGen:Trojan.Heur.PT.frZ@aisNjGn (B)
F-SecureTrojan.TR/Crypt.NSPM.Gen
VIPREGen:Trojan.Heur.PT.frZ@aisNjGn
TrendMicroTROJ_GEN.R03BC0RAG24
Trapminemalicious.high.ml.score
SophosMal/EncPk-BN
IkarusWorm.Win32.Soltern
GDataGen:Trojan.Heur.PT.frZ@aisNjGn
GoogleDetected
AviraTR/Crypt.NSPM.Gen
Kingsoftmalware.kb.b.984
XcitiumPacked.Win32.Klone.~KA@1jbcwy
ArcabitTrojan.Heur.PT.E9CE9F
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/LdPinch.N.gen!Eldorado
AhnLab-V3Win32/RPCrypt.Suspicious
McAfeeArtemis!6416F3A7312D
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.NSPack
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0RAG24
RisingBackdoor.Hupigon!8.B57 (TFE:1:p2w2lVEPLaI)
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.Mabezat.Dam
FortinetW32/PossibleThreat
AVGWin32:RPoly [Cryp]
Cybereasonmalicious.942e41
DeepInstinctMALICIOUS

How to remove Win32:RPoly [Cryp]?

Win32:RPoly [Cryp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment