Trojan

Trojan.Crypt.NKN removal instruction

Malware Removal

The Trojan.Crypt.NKN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.NKN virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Connects to an IRC server, possibly part of a botnet

Related domains:

irc.zief.pl

How to determine Trojan.Crypt.NKN?


File Info:

crc32: 49445815
md5: 2b9fac8500efb9b8782b4c86610dec1b
name: 2B9FAC8500EFB9B8782B4C86610DEC1B.mlw
sha1: badc59267a48c8bd80aac1f24a97a7a42b428aba
sha256: 388da8bf0c7966efc226244102b7d84ad8003e57abe113addca9f9d0d4a18e76
sha512: c1086979808e6575da44b6b9b5fcb1cff88be83bedda6ca49675a9d274308b54058d06185e59ccb1d15db4acfaf2f4a48f7b02e57426dca9964795c0b58ee7e4
ssdeep: 3072:BJ24REGKS7gzd2rI/ITJghl51Fs6FBugo1yO:ZE+gz14AzBu/1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Crypt.NKN also known as:

BkavW32.Vetor.PE
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Krypt.12
FireEyeGeneric.mg.2b9fac8500efb9b8
CAT-QuickHealW32.Virut.G
ALYacGen:Heur.Krypt.12
CylanceUnsafe
VIPREVirus.Win32.Virut.ce (v)
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Heur.Krypt.12
InvinceaML/PE-A + W32/Scribble-B
BaiduWin32.Virus.Virut.gen
CyrenW32/Virut.AI
SymantecW32.Virut.CF
TotalDefenseWin32/Virut.17408
APEXMalicious
AvastWin32:Vitro [Inf]
ClamAVWin.Trojan.Vbkryjetor-7588409-0
KasperskyVirus.Win32.Virut.ce
NANO-AntivirusVirus.Win32.Virut.hpeg
ViRobotWin32.Virut.Gen.C
TencentVirus.Win32.Virut.tt
Ad-AwareGen:Heur.Krypt.12
SophosW32/Scribble-B
ComodoVirus.Win32.Virut.CE@1fhkga
F-SecureMalware.W32/Virut.Gen
DrWebWin32.HLLW.Autoruner2.18595
ZillyaVirus.Virut.Win32.27
TrendMicroPE_VIRUX.A-1
McAfee-GW-EditionBehavesLike.Win32.Virut.cc
EmsisoftGen:Heur.Krypt.12 (B)
IkarusVirus.Virut
JiangminWin32/Virut.bn
AviraW32/Virut.Gen
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftVirus:Win32/Virut.BN
ArcabitTrojan.Krypt.12
ZoneAlarmVirus.Win32.Virut.ce
GDataGen:Heur.Krypt.12
CynetMalicious (score: 100)
AhnLab-V3Win32/Virut.F
Acronissuspicious
McAfeeW32/Virut.af.gen
TACHYONVirus/W32.Virut.Gen
VBA32Virus.Virut.06
MalwarebytesTrojan.Crypt.NKN
PandaW32/Sality.AO
ZonerTrojan.Win32.Virut.22005
ESET-NOD32Win32/Virut.NBP
TrendMicro-HouseCallPE_VIRUX.A-1
RisingVirus.Virut!1.A08B (CLASSIC)
YandexTrojan.GenAsa!gFG1DtlVO0g
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Virut.CE
FortinetW32/Virut.CE
BitDefenderThetaGen:NN.ZevbaF.34634.jm0@aigNdwg
AVGWin32:Vitro [Inf]
Cybereasonmalicious.500efb
Qihoo-360Virus.Win32.VirutChangeEntry.A

How to remove Trojan.Crypt.NKN?

Trojan.Crypt.NKN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment