Malware

Win32/Kryptik.AJQK removal

Malware Removal

The Win32/Kryptik.AJQK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AJQK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.AJQK?


File Info:

name: DA2AAC33B86AA211A973.mlw
path: /opt/CAPEv2/storage/binaries/de380adaea5871361eb2390b92fe88feada11c0929e3636f691f171c6879955f
crc32: 5479A63C
md5: da2aac33b86aa211a973bea14ee67d53
sha1: 487d3494325233f50804074660c3b4bc59212e51
sha256: de380adaea5871361eb2390b92fe88feada11c0929e3636f691f171c6879955f
sha512: 1ff6093b595494994f873d6cb8ce4900336ececaf1b2fd859166f30a12b1610ed1149756ce2cba1296bca31d021561a9f578b8412117dc68badd29363b8d1e4f
ssdeep: 6144:Sm1aZCkx2o4sGmn8rv4DNpTaQzRmPQ8QiG8AKMEvxkNGkfnCJ49ijMXC:SFqon8rvgp49VMEZMfna49ijM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147841233E5458845C8ADFDF6E1534B6E43AFDE1115B86A489BC470AB8EBC1AE7831C09
sha3_384: c29fe7d040359026a3c37e118c721798c60d08e964507651720c8281732745e5554caa56607e529e261afeefdc2adca8
ep_bytes: b848304000ff08ff106a00a180304000
timestamp: 2012-01-18 07:21:34

Version Info:

0: [No Data]

Win32/Kryptik.AJQK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.da2aac33b86aa211
CAT-QuickHealFraudTool.Security
McAfeeFakeAV-SecurityTool.fh
VIPRETrojan.VIZ.Gen.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005042e61 )
K7GWTrojan ( 005042e61 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36308.xqW@aizq00dG
VirITFraudTool.Win32.Generic.Y
CyrenW32/FakeAlert.UN.gen!Eldorado
SymantecSecShieldFraud!gen7
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AJQK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.FakeAV.vrtol
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
AvastWin32:Susn-AK [Trj]
SophosTroj/FakeAV-FWY
DrWebTrojan.Fakealert.32747
ZillyaTrojan.FakeAV.Win32.216072
TrendMicroTROJ_FKEALRT.SMJ
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fc
Trapminemalicious.high.ml.score
EmsisoftTrojan.VIZ.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.VIZ.Gen.1
JiangminTrojan/SmartFortress2012.cal
AviraTR/AD.FakeAV.ybkhf
Antiy-AVLTrojan[Ransom]/Win32.Mbro
XcitiumTrojWare.Win32.Kryptik.AJQS@4q3go5
ArcabitTrojan.VIZ.Gen.1
ViRobotTrojan.Win32.A.SmartFortress2012.378880.DL
MicrosoftRogue:Win32/Winwebsec
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R26384
VBA32TrojanFakeAV.SmartFortress2012
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=88)
Cylanceunsafe
TrendMicro-HouseCallTROJ_FKEALRT.SMJ
RisingTrojan.FakeAV!1.9972 (CLASSIC)
YandexTrojan.GenAsa!ocVC0e7APLo
IkarusTrojan-PSW.Win32.Tepfer
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AGAI!tr
AVGWin32:Susn-AK [Trj]
Cybereasonmalicious.3b86aa
PandaAdware/SystemTool

How to remove Win32/Kryptik.AJQK?

Win32/Kryptik.AJQK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment