Malware

About “Troj/Krypt-AAI” infection

Malware Removal

The Troj/Krypt-AAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Krypt-AAI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Troj/Krypt-AAI?


File Info:

name: 930F819B0A984A2F55DD.mlw
path: /opt/CAPEv2/storage/binaries/5b416bdea419020c3c0a7b18c0db05fb5e483cceb64b585ff8dc6fd9aeb8c8d3
crc32: 2A107A7D
md5: 930f819b0a984a2f55ddf5ac340847c8
sha1: 4fb5c3f22171189b3e26efd763724b41430e1d31
sha256: 5b416bdea419020c3c0a7b18c0db05fb5e483cceb64b585ff8dc6fd9aeb8c8d3
sha512: 2e6ef2e44ea7a8ac1d224dd755d8faa0d60fc8eeabc4f253008421b2c2b834968e5926bed88977144ec77fdd65e86912ec90ab44859330a53de9426207cf018d
ssdeep: 3072:+alzZimpw7AN9JB4k0msTI3rq+jB1i5n2tgBdEqGzATPWZuXejxE:+sz14AX4k0mAI3fB11rpE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19F044A25B2C250B6C5764470B4DDC770B87EB8B00A115EEB674817FB1AA0FC2B7E69C5
sha3_384: 781730b50dee58f09a1c3267aaa2e52c8eca5abdcdfd8d25f9bc7483a4ccf3799e9db5128a173c29e9e67b27908d1465
ep_bytes: e8e2020000e974feffff558bec83ec0c
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: This is a legitimate application.
CompanyName: Wissol Petreleum Georgia
FileDescription: Wissol Petreleum Georgia Product
FileVersion: 877
InternalName: RP8fe8cSwLZr
LegalCopyright: © Wissol Petreleum Georgia All rights reserved.
LegalTrademarks: © Wissol Petreleum Georgia Trademarks
OriginalFilename: e0K1FNp8.exe
ProductName: GLl8Lox6pF
ProductVersion: 877
Translation: 0x0407 0x04b0

Troj/Krypt-AAI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Injurer.4!c
MicroWorld-eScanTrojan.GenericKDZ.101672
ClamAVWin.Malware.Dacic-10006009-0
McAfeeGenericRXWF-GF!930F819B0A98
MalwarebytesTrojan.MalPack
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a7ab71 )
AlibabaTrojan:Win32/Injurer.2e29f036
K7GWTrojan ( 005a7ab71 )
BitDefenderThetaGen:NN.ZexaE.36318.lu2@aapMKDei
CyrenW32/Kryptik.KDE.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTZZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Injurer.gen
BitDefenderTrojan.GenericKDZ.101672
NANO-AntivirusTrojan.Win32.Injurer.jxceny
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf06b6
EmsisoftTrojan.GenericKDZ.101672 (B)
F-SecureTrojan.TR/Crypt.Agent.xdsqs
DrWebTrojan.Siggen21.5195
VIPRETrojan.GenericKDZ.101672
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.930f819b0a984a2f
SophosTroj/Krypt-AAI
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1SQ6TU6
JiangminTrojan.Injurer.f
AviraTR/Crypt.Agent.xdsqs
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Generic.D18D28
ViRobotTrojan.Win.Z.Agent.189769.B
ZoneAlarmHEUR:Trojan.Win32.Injurer.gen
MicrosoftTrojan:Win32/Redlinestealer!ic
GoogleDetected
AhnLab-V3Trojan/Win.REDLINESTEALER.R589955
ALYacTrojan.GenericKDZ.101672
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/GdSda.A
RisingTrojan.ShellCodeRunner!1.E830 (CLASSIC)
IkarusTrojan.Win32.Redline
MaxSecureTrojan.W32.Injurer.gen
FortinetW32/GenKryptik.GLDD!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Krypt-AAI?

Troj/Krypt-AAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment