Skip to main content

Cryptlab

Classification

Category:

Malware

Aliases:

  • MtE
  • Mutation Engine

Summary

This is not really a virus, but a "add-on" product supplied by the person who calls himself Dark Avenger. It can be used to give any virus a "polymorphic" ability, making it undetectable with a signature-based scanner.

Removal

Technical Details

Instead an algorithmic approach is used, which may (theoretically) produce false alarms. So, if F-Secure anti-virus products ever report a single file as containing MtE, don't be too alarmed - it might just be a false positive. If you get an alarm from a data file (non-executable), it's a certain false positive. Send a sample and we'll fix it.

One known false alarm is a file called 120492_v.dxf. If you find MtE from this file, simply ignore it.

Another known false alarms is from a data file called bf1g2.acm. This file is from a game called Baldur's Gate. If you find MtE from this file, simply ignore the false alarm. We are working to fix this.

Several viruses are known to make use of this Mutation Engine:

Variant:Pogue

Other: Resident, COM-files

A variant of the Gotcha virus.

Variant:Dedicated, Fear

Other:Non-Resident, COM-files

Those two viruses are almost identical - but with different text messages. They would be considered totally unremarkable, if not for the inclusion of the engine.

Variant:Groove

Other: Resident, COM/EXE-files

This virus is targeted against several anti-virus product, attacking their data files.

Variant:Cryptlab

Other: Non-Resident, COM-files

Unknown effects.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.