Malware

Troj/Krypt-ADH (file analysis)

Malware Removal

The Troj/Krypt-ADH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Krypt-ADH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Troj/Krypt-ADH?


File Info:

name: 94317B1CA26DF0FA895F.mlw
path: /opt/CAPEv2/storage/binaries/270d4be93953a401f615504e897413265dcaeb99aebb840c4ed5e54ceef33a8e
crc32: FEAFFFF4
md5: 94317b1ca26df0fa895f6d848b7a3a2e
sha1: 837e847a6d6c2fde626142688bfe5d9200b9b796
sha256: 270d4be93953a401f615504e897413265dcaeb99aebb840c4ed5e54ceef33a8e
sha512: 413f8366d9da0d37c155157de838fd54ec07ee0c8ea07b8ab7c7f09365474bd3791bec2401a8b7609485578683df52f78e77343d738ae643d57ed3bbdbc72d75
ssdeep: 3072:uA3PzGScDkVVf07CzxSuJx8qrRkUfQmV4gp/fCaAxw27q:uOyScQVVf3xSuJx1HflD96Lx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0F3BF2173B2D872DB96153059BAC5701A6D7C323E37424B639C262F5FB0ED09A2E763
sha3_384: 4d3f9564a027fd9a23aed6635415ad93968693de66989c10fb464122f4f3bd352331da7d5be71f41ccf095b483f90432
ep_bytes: e84b2e0000e989feffff8bff558bec81
timestamp: 2023-03-29 23:45:44

Version Info:

FileVersion: 12.3.3.593
ProductVersion: 2.16.10.51
InternalName: Slupido
CompanyName: Torchok
Translation: 0x149d 0x0235

Troj/Krypt-ADH also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
FireEyeGeneric.mg.94317b1ca26df0fa
Cylanceunsafe
SangforRansom.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.a6d6c2
BitDefenderThetaGen:NN.ZexaF.36744.kq0@aebNhuki
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
TencentTrojan.Win32.Obfuscated.gen
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ADH
KingsoftWin32.Troj.Undef.a
ZoneAlarmUDS:DangerousObject.Multi.Generic
GoogleDetected
Acronissuspicious
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Generic@AI.100 (RDML:hU/RbWmTY6LBG2K7uGNWnA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Troj/Krypt-ADH?

Troj/Krypt-ADH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment