Malware

Win64/Kryptik.CSP information

Malware Removal

The Win64/Kryptik.CSP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Kryptik.CSP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Win64/Kryptik.CSP?


File Info:

name: 2A64EF4C7B1FA6FB47FD.mlw
path: /opt/CAPEv2/storage/binaries/3a6388b5f0f4c5bf7e055ef67900fc6454f0c96d0135961f3b4bb81a4d744e6a
crc32: FB469316
md5: 2a64ef4c7b1fa6fb47fdb947d1ba1ad2
sha1: a94103725e194289af3265e32942fd117bce5114
sha256: 3a6388b5f0f4c5bf7e055ef67900fc6454f0c96d0135961f3b4bb81a4d744e6a
sha512: 71f8dc991fc47e6b9ff41635eae34600c6574e8de41ca36766a10cb641a7370e2900f16e1c6458653745a9cf54dfe5c1a9a5086d9dcc7dfad07df96f58d70ad0
ssdeep: 24576:XdqNdsgjRvTlFALxIALWXZ4flnvgyQCAl:tidDt
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T111357DAEAB609DC6CA4B45B1CC720D941EA52B330545E2CED1E752420E17BF7DE1EA3C
sha3_384: 2d80a0661aea36b403cc225c88dd8e1fb2050961955dbc22d64a22a09ef03e4da64a761329caa9b25ae67aadc9b43e86
ep_bytes: 4883ec28e85b0600004883c428e972fe
timestamp: 2021-11-26 04:13:17

Version Info:

0: [No Data]

Win64/Kryptik.CSP also known as:

MicroWorld-eScanTrojan.GenericKD.47501866
FireEyeTrojan.GenericKD.47501866
ALYacTrojan.GenericKD.47501866
CylanceUnsafe
AlibabaTrojan:Win32/Cobalt.ae4d1cee
K7GWTrojan ( 0058a6b61 )
K7AntiVirusTrojan ( 0058a6b61 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Kryptik.CSP
AvastWin64:Trojan-gen
KasperskyTrojan.Win32.Cobalt.hgu
BitDefenderTrojan.GenericKD.47501866
Ad-AwareTrojan.GenericKD.47501866
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win64.Injector.tm
EmsisoftTrojan.GenericKD.47501866 (B)
Paloaltogeneric.ml
GDataWin32.Trojan.CobaltStrike.5N5V3T
AviraTR/AD.CobaltStrike.hljpu
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!2A64EF4C7B1F
MAXmalware (ai score=87)
APEXMalicious
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW64/Kryptik.CSP!tr
AVGWin64:Trojan-gen
PandaTrj/CI.A

How to remove Win64/Kryptik.CSP?

Win64/Kryptik.CSP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment