Trojan

How to remove “Trojan-PSW.Win32.Cryptnot”?

Malware Removal

The Trojan-PSW.Win32.Cryptnot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Cryptnot virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Trojan-PSW.Win32.Cryptnot?


File Info:

crc32: 1A3FA540
md5: 7cfbf5ddc9d80df8544a962185448451
name: 7CFBF5DDC9D80DF8544A962185448451.mlw
sha1: f37b0979ee3f05bc5e7a0697f5cabb0758c710d4
sha256: 2dd214b7750c889a14bb6c1be4ff3b32e1bce2fba8d274de69b36b442486a1c6
sha512: 1ae1c5b908de98edf40ae7e7993128730215e52aa662731d89570c1cd77411d40805b7e8385d749f13b8f40fa4a2fe982119c06f6167207b812e1cc761ab4e3c
ssdeep: 12288:HXnENgrrYmJR47aa4AodYhpS62pAx8nGpCpBNG8cjU3Qm3BP+nx/SQ:HXENgIc47a9dYf1GGqBN+jpm3BGMQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x48e5 0x035a

Trojan-PSW.Win32.Cryptnot also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.76106
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Kryptik.1d1087d8
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9ee3f0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLNE
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.Win32.Cryptnot.gen
BitDefenderTrojan.GenericKDZ.76106
MicroWorld-eScanTrojan.GenericKDZ.76106
Ad-AwareTrojan.GenericKDZ.76106
SophosMal/Generic-R + Troj/Kryptik-TR
BitDefenderThetaGen:NN.ZexaF.34758.Xu0@ai6xXdcG
TrendMicroRansom.Win32.STOP.SMYXBFX.hp
McAfee-GW-EditionBehavesLike.Win32.Lockbit.bc
FireEyeGeneric.mg.7cfbf5ddc9d80df8
EmsisoftTrojan.GenericKDZ.76106 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Racealer.cln
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_74%
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Caynamer.A!ml
GridinsoftTrojan.Win32.Packed.lu!heur
GDataTrojan.GenericKDZ.76106
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.D792 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HLNE!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Cryptnot?

Trojan-PSW.Win32.Cryptnot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment