Trojan

Trojan:Win32/Krypter.AA!MTB removal

Malware Removal

The Trojan:Win32/Krypter.AA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Krypter.AA!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua
kotob.top
pqkl.org

How to determine Trojan:Win32/Krypter.AA!MTB?


File Info:

crc32: 3C01A2B2
md5: 561ee0ec40a362d4ad041b7c51189e66
name: 561EE0EC40A362D4AD041B7C51189E66.mlw
sha1: c186bacfe9a37670dfd82b554cb7b97e56df9b6c
sha256: 2859170237e0e4e6a425c438afa13d1955e28d73d06f8229979752db20de0c4c
sha512: da45270e9bbc0186047aeaaee9a80756ada9cf8fe771b61ec3e116f3c840eb28539b7665465da6eae806c546d9e37ed07a859c097458cb369b5f3270dbee9f73
ssdeep: 12288:RXgtkKni4aJd74ws21WI/iZXscuuZJr92Be0I1SBaj3701Ylq:FgDi4K74rKes8vrL0dy7SY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 15.54.32.31
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0115 0x046a

Trojan:Win32/Krypter.AA!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00589d2d1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.fe9a37
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan-Ransom.Win32.Stop.gen
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.RC0@a8rW2KaI
McAfee-GW-EditionBehavesLike.Win32.Drixed.jc
FireEyeGeneric.mg.561ee0ec40a362d4
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_76%
MicrosoftTrojan:Win32/Krypter.AA!MTB
Acronissuspicious
McAfeePacked-GDV!561EE0EC40A3
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@ML.98 (RDML:jJIQdStZ417OXDnU6e2mrw)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware

How to remove Trojan:Win32/Krypter.AA!MTB?

Trojan:Win32/Krypter.AA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment