Malware

ML/PE-A + Troj/Kryptik-JX (file analysis)

Malware Removal

The ML/PE-A + Troj/Kryptik-JX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Kryptik-JX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Sindhi
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine ML/PE-A + Troj/Kryptik-JX?


File Info:

crc32: 481B7E91
md5: 2d1df1dac6a0cb33bfa1d890c1319886
name: 2D1DF1DAC6A0CB33BFA1D890C1319886.mlw
sha1: c7a74e783d759a2953a66eb40cc4873848b99743
sha256: b836ba06cd0e78c2ea832740acdb9663856c5b7f9a892640634b2046e82265c1
sha512: 0c23cfcedadd3d46794900f4fcf615034d7a0b4247e392d297124d336a51577a86ae66a2ff0a25f14dac7a4edf498bedb192e8bd821e86d95196418dbf45dada
ssdeep: 6144:9l2ka0Yp9gTCE20B/ctvcAKbUMw8r4Kxq9eRiQ8j65d8I5Wbg1mdzPB+w9rjJSO:9lda9pWCE20B/cqAKbUMwEGKiQ8j65y
type: PE32 executable (GUI) Intel 80386, for MS Windows, AIN 1.x self-extracting archive

Version Info:

0: [No Data]

ML/PE-A + Troj/Kryptik-JX also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005532e31 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.BrsecmonE.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1684671
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.b8fcf917
K7GWTrojan ( 005519d41 )
Cybereasonmalicious.ac6a0c
CyrenW32/Kryptik.AAM.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GUWX
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Generic-9853074-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.DelShad.fugrpa
MicroWorld-eScanTrojan.BrsecmonE.1
TencentWin32.Trojan.Generic.Hrfp
Ad-AwareTrojan.BrsecmonE.1
SophosML/PE-A + Troj/Kryptik-JX
BitDefenderThetaGen:NN.ZexaF.34236.xyW@a4z49ScG
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.2d1df1dac6a0cb33
EmsisoftTrojan.Generic.EF (A)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1124543
Antiy-AVLTrojan/Generic.ASMalwS.2C1BBF5
MicrosoftTrojan:Win32/Kryptik.DR!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
GDataTrojan.BrsecmonE.1
AhnLab-V3Trojan/Win32.Ransom.R283296
Acronissuspicious
McAfeeTrojan-FQYS!2D1DF1DAC6A0
MAXmalware (ai score=84)
VBA32Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@ML.96 (RDML:QcaER0eonMEs6pODbagrPA)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74459900.susgen
FortinetW32/GenKryptik.DQHN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove ML/PE-A + Troj/Kryptik-JX?

ML/PE-A + Troj/Kryptik-JX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment