Malware

Troj/Kryptik-NF (file analysis)

Malware Removal

The Troj/Kryptik-NF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Kryptik-NF virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Troj/Kryptik-NF?


File Info:

crc32: DF2A7B83
md5: abfc2850ed5e1c9d5aa4484f7c9f9bc5
name: upload_file
sha1: 61231cee63e3a0a2863aaf55922c23e22a483ece
sha256: ce2c01bbc12cb5d903130e68a4e34056f292ebfdb307a185076c3e99b6f98ef3
sha512: 6a74f4ad42667118cc7c7518e288d1fe1ab49989be0dfdafef080e367b655a41b74932d87b4009b3f5004f287e484641047bd192b84482670d577930c7507ee3
ssdeep: 24576:Io5q+1iB1cqU+qb15MJH4XUFi7Xloby8sfPyb:d5qvBhqRqJHAUs71oO8wP
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 HP 2015
Assembly Version: 1.0.0.0
InternalName: x671bx987e.exe
FileVersion: 1.0.0.0
CompanyName: HP
LegalTrademarks:
Comments:
ProductName: LevelEditor
ProductVersion: 1.0.0.0
FileDescription: LevelEditor
OriginalFilename: x671bx987e.exe

Troj/Kryptik-NF also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35076365
FireEyeGeneric.mg.abfc2850ed5e1c9d
CAT-QuickHealTrojanSpy.MSIL
McAfeePWS-FCSU!ABFC2850ED5E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderTrojan.GenericKD.35076365
K7GWTrojan ( 005723be1 )
K7AntiVirusTrojan ( 005723be1 )
TrendMicroTrojanSpy.MSIL.NOON.THKOFBO
BitDefenderThetaGen:NN.ZemsilF.34590.qn0@aW7uCIi
CyrenW32/MSIL_Kryptik.CAS.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
AlibabaBackdoor:MSIL/NanoBot.7e74554f
ViRobotTrojan.Win32.Z.Agent.1317888.EX
Ad-AwareTrojan.GenericKD.35076365
SophosTroj/Kryptik-NF
F-SecureTrojan.TR/AD.AgentTesla.fjipn
DrWebTrojan.Packed2.42665
InvinceaMal/Generic-R + Troj/Kryptik-NF
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.MSIL.bafj
AviraTR/AD.AgentTesla.fjipn
MAXmalware (ai score=86)
Antiy-AVLTrojan[Spy]/MSIL.Noon
MicrosoftTrojan:MSIL/AgentTesla.MV!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D217390D
AhnLab-V3Trojan/Win32.Noon.R354756
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
GDataTrojan.GenericKD.35076365
CynetMalicious (score: 85)
ESET-NOD32a variant of MSIL/Kryptik.YMQ
ALYacSpyware.AgentTesla
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.NOON.THKOFBO
TencentMsil.Trojan-spy.Noon.Lriq
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.e63e3a
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.Spy.beb

How to remove Troj/Kryptik-NF?

Troj/Kryptik-NF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment