Malware

Win32/Kryptik.AJOL removal instruction

Malware Removal

The Win32/Kryptik.AJOL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AJOL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings

How to determine Win32/Kryptik.AJOL?


File Info:

name: 97CEABE2068777D47F8A.mlw
path: /opt/CAPEv2/storage/binaries/53e53942280b9c342b6f522e822e2bbe18b328665e801bf82935ebc2ea3086b7
crc32: B9DE38FF
md5: 97ceabe2068777d47f8a9c057b4fdcbe
sha1: 102c72b25284f0a06043d3a8efb1d1d56c292236
sha256: 53e53942280b9c342b6f522e822e2bbe18b328665e801bf82935ebc2ea3086b7
sha512: 07c287fcfce04e11ebf813bdd58d39a668479f305577c1456da5d6064c72a7f1454ee1a81e44845910ad46ac2293222c79df1e0b480951d7a635c6fa8d8643d4
ssdeep: 6144:0nQjvjVcVAC2FXgEr8fE0ASg3/YQvRNMVlJi41fv4Dw:0nYvjVkCrSvoZNyl5fwD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7841233BD478C00D2B9B5BB8ABB8F659B43CC516A14394017D8B9BB7DB5506B8B0398
sha3_384: 92d0c81c246f1ce52b1389f8c50abe4377026832740ce7f1a215d6269357f360d6ec9ac6ad142881f89af5fdf0d9e39f
ep_bytes: ff150c3040006a00ff155830400033d2
timestamp: 2012-01-18 07:21:34

Version Info:

0: [No Data]

Win32/Kryptik.AJOL also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.VIZ.Gen.1
CAT-QuickHealFraudTool.Security
ALYacTrojan.VIZ.Gen.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3810005
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005042e61 )
AlibabaMalware:Win32/km_2433de3.None
K7GWTrojan ( 005042e61 )
Cybereasonmalicious.206877
VirITTrojan.Win32.FakeAV_s.FF
CyrenW32/FakeAlert.UN.gen!Eldorado
SymantecSecShieldFraud!gen7
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AJOL
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Winwebsec-9945498-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Fakealert.wsixe
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:FakeAV-DTB [Trj]
TencentWin32.Trojan.Generic.Hvte
Ad-AwareTrojan.VIZ.Gen.1
SophosML/PE-A + Troj/FakeAV-FWY
ComodoTrojWare.Win32.Kryptik.AISL@4psha1
DrWebTrojan.Fakealert.32747
VIPRETrojan.VIZ.Gen.1
TrendMicroTROJ_FKEALRT.SMJ
McAfee-GW-EditionPWS-Zbot.gen.ain
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.97ceabe2068777d4
EmsisoftTrojan.VIZ.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/SmartFortress2012.bxr
WebrootW32.Rogue.Gen
AviraTR/FakeAlert.urz
Antiy-AVLTrojan/Generic.ASMalwS.1F6
MicrosoftRogue:Win32/Winwebsec
ViRobotTrojan.Win32.A.SmartFortress2012.381440.P
GDataTrojan.VIZ.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R34595
Acronissuspicious
McAfeePWS-Zbot.gen.ain
MAXmalware (ai score=83)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesTrojan.LameShield
TrendMicro-HouseCallTROJ_FKEALRT.SMJ
RisingTrojan.FakeAV!1.9972 (CLASSIC)
YandexTrojan.GenAsa!boPuwHq5SCg
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.Malware.4338504.susgen
FortinetW32/Kryptik.AGAI!tr
BitDefenderThetaAI:Packer.A70B299F21
AVGWin32:FakeAV-DTB [Trj]
PandaAdware/SystemTool
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.AJOL?

Win32/Kryptik.AJOL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment