Trojan

Trojan.Crypt.NP removal tips

Malware Removal

The Trojan.Crypt.NP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.NP virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Crypt.NP?


File Info:

name: 72A593F8B31C22CD626F.mlw
path: /opt/CAPEv2/storage/binaries/53ff11a158a81f46ecef582b2a489201b0fd817fce72e32b72338b10f5e12e34
crc32: B9D511C9
md5: 72a593f8b31c22cd626f0a12d3d96285
sha1: f3635242888a3bb6bee8c08ed7a715169f25833d
sha256: 53ff11a158a81f46ecef582b2a489201b0fd817fce72e32b72338b10f5e12e34
sha512: ffdd9b42e256c00b38f497d9a126149448f4655d932fddb4e7b19531981f943708b47fa598207d11824395e7cf328b91fa9ab1be7f8dadabbbc887b6abad0137
ssdeep: 24576:hAbtGjxBimTRynd7wKzu4JkKYe2Num6qps6:JzTRynd7wKzo/NC6
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T11F259D317D819171EEF350FA46ECB523896DA8F01F2247CF568607EECE246D16E31A86
sha3_384: cab0e892d62c4edaa281f3ea04905dcd3d7ff0821628a8b59e6873971a66faa6a8436af6695d813c8ceb7006b6fb148a
ep_bytes: e9ae740400e974db0500e913f90400e9
timestamp: 2022-08-26 21:24:14

Version Info:

0: [No Data]

Trojan.Crypt.NP also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.61533490
FireEyeTrojan.GenericKD.61533490
ALYacTrojan.GenericKD.61533490
VIPREGen:Variant.Lazy.238003
SangforInfostealer.Win32.Agent.Vuko
K7AntiVirusTrojan ( 0059777e1 )
BitDefenderTrojan.GenericKD.61533490
K7GWTrojan ( 0059777e1 )
ArcabitTrojan.Generic.D3AAED32
SymantecTrojan Horse
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/GenKryptik.FZIE
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXCH1Z
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Mokes.gen
AlibabaBackdoor:Win32/Mokes.bbd64f5c
CynetMalicious (score: 99)
RisingBackdoor.Mokes!8.619 (TFE:5:1JK1U0PCZmJ)
Ad-AwareTrojan.GenericKD.61533490
EmsisoftTrojan.GenericKD.61533490 (B)
DrWebTrojan.PWS.Steam.28157
TrendMicroTrojanSpy.Win32.REDLINE.YXCH1Z
IkarusTrojan.Win32.RedlineStealer
AviraTR/Kryptik.nyffj
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1KSF7BU
GoogleDetected
AhnLab-V3Trojan/Win.PWSX-gen.R512598
McAfeeArtemis!72A593F8B31C
MAXmalware (ai score=86)
MalwarebytesTrojan.Crypt.NP
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]

How to remove Trojan.Crypt.NP?

Trojan.Crypt.NP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment