Malware

Win64/Kryptik.CRI information

Malware Removal

The Win64/Kryptik.CRI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Kryptik.CRI virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win64/Kryptik.CRI?


File Info:

name: BA6633096B154755EDD0.mlw
path: /opt/CAPEv2/storage/binaries/23515bd55879fdbbd12c88729c2954e774a7d41a97cb83634a28d1b96741b671
crc32: FDA31194
md5: ba6633096b154755edd099b312836868
sha1: a5839553a6f7c44932acf826060a87fdcc9f99f9
sha256: 23515bd55879fdbbd12c88729c2954e774a7d41a97cb83634a28d1b96741b671
sha512: 6779db39169e75626ee26a89c894d991e6079b86d46515837a08c601d22d7d815c3e88a8c971743730525c49e0f41e250e59210ec3bc5466ef93325d691a581d
ssdeep: 1536:n5KI+x2EVnhpHMQ4pJ340kIt5KLU7XocR+goW5:5tmnhpk93u+XoT9
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1C9530293C72B24FCDD3F823199B531A5ABE18A2D3DDEE74B4E6205CD730094C950B6A9
sha3_384: f9352459e9cec5308f14de2c9858997d8f8ef8b65f27a99bea81f0e43b3de3c8ef340cd88941c11e0a8089e85f3535c2
ep_bytes: 53565755488d355a12ffff488dbedb1f
timestamp: 2021-11-17 06:40:37

Version Info:

0: [No Data]

Win64/Kryptik.CRI also known as:

LionicTrojan.Win64.Shelma.4!c
DrWebBackDoor.CobaltStrike.2
MicroWorld-eScanTrojan.GenericKD.38228115
FireEyeTrojan.GenericKD.38228115
McAfeeRDN/Generic.dx
CylanceUnsafe
K7AntiVirusTrojan ( 0058923b1 )
K7GWTrojan ( 0058923b1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.CRI
TrendMicro-HouseCallTROJ_GEN.R002C0PLC21
Paloaltogeneric.ml
KasperskyTrojan.Win64.Shelma.rcq
BitDefenderTrojan.GenericKD.38228115
AvastFileRepMalware
Ad-AwareTrojan.GenericKD.38228115
EmsisoftTrojan.GenericKD.38228115 (B)
F-SecureTrojan.TR/Kryptik.cdxzu
TrendMicroTROJ_GEN.R002C0PLC21
McAfee-GW-EditionBehavesLike.Win64.Generic.kc
SophosMal/Generic-S
IkarusTrojan.Win64.Crypt
GDataMSIL.Backdoor.Rozena.56RRGK
AviraTR/Kryptik.cdxzu
Antiy-AVLTrojan/Win64.Kryptik
ArcabitTrojan.Generic.D2475093
MicrosoftVirTool:Win32/Sysdupate.gen!C
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4826516
VBA32Trojan.Win64.Shelma
ALYacTrojan.GenericKD.38228115
MAXmalware (ai score=88)
APEXMalicious
YandexTrojan.Shelma!XtyNL0My30U
MaxSecureTrojan.Malware.300983.susgen
FortinetW64/Kryptik.CRI!tr
AVGFileRepMalware
Cybereasonmalicious.3a6f7c

How to remove Win64/Kryptik.CRI?

Win64/Kryptik.CRI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment