Spy Trojan

TrojanSpy:Win32/Kratos.A!bit (file analysis)

Malware Removal

The TrojanSpy:Win32/Kratos.A!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Kratos.A!bit virus can do?

  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system

Related domains:

okno34.xyz

How to determine TrojanSpy:Win32/Kratos.A!bit?


File Info:

crc32: 06484126
md5: c40ba19bd7e7cd2db713144f06fdd45a
name: C40BA19BD7E7CD2DB713144F06FDD45A.mlw
sha1: 5387cc3e81f5e5c3866504cbff22bac65a6c3a07
sha256: 20488575c21bdd094c0edc79753cc64e53bf723e7b26991177f80277d08090bf
sha512: ef631674f59f50af17d1207ff3fe30abead27cfb7f1ed165a864a6dbfc2a1bb060009d3d611c919ffa68499c30758ecdcd499a09034d69d10f00c4f9b49742e5
ssdeep: 12288:1fQSapkRL1DjPF2VsLnQZ4zpTLS4eunnE3gC7rn63YBxVJv+Vete80:1fQSapkRNPMabQZ6pTuQn6Hn63IwVet
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Kratos.A!bit also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 0053229a1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23915
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.RP.QCW@byca2Gpi
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7GWSpyware ( 0053229a1 )
Cybereasonmalicious.bd7e7c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.PLA
APEXMalicious
AvastFileRepMalware
ClamAVWin.Coinminer.HiddenShock-6605339-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.RP.QCW@byca2Gpi
NANO-AntivirusTrojan.Win32.Androm.fcrttr
MicroWorld-eScanGen:Trojan.Heur.RP.QCW@byca2Gpi
TencentWin32.Backdoor.Androm.Suxf
Ad-AwareGen:Trojan.Heur.RP.QCW@byca2Gpi
SophosMal/Generic-S
ComodoTrojWare.Win32.Spy.Kratos.PYN@7r36tj
BitDefenderThetaAI:Packer.32B3CA101F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXFN-GE!C40BA19BD7E7
FireEyeGeneric.mg.c40ba19bd7e7cd2d
EmsisoftGen:Trojan.Heur.RP.QCW@byca2Gpi (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1103392
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.262C203
MicrosoftTrojanSpy:Win32/Kratos.A!bit
ArcabitTrojan.Heur.RP.EA2CC7
GDataGen:Trojan.Heur.RP.QCW@byca2Gpi
AhnLab-V3Malware/Win32.Generic.C2520626
McAfeeGenericRXFN-GE!C40BA19BD7E7
MAXmalware (ai score=96)
MalwarebytesMalware.AI.160231725
PandaTrj/GdSda.A
RisingStealer.Arkei!1.B243 (CLASSIC)
YandexTrojan.GenAsa!ZRCnAtXBL0Q
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.PKU!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove TrojanSpy:Win32/Kratos.A!bit?

TrojanSpy:Win32/Kratos.A!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment