Malware

About “Win32/Kryptik.AWTJ” infection

Malware Removal

The Win32/Kryptik.AWTJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AWTJ virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Win32/Kryptik.AWTJ?


File Info:

crc32: 3A1F25EC
md5: d5312fb6afc502145c1d75e5b90a72dc
name: D5312FB6AFC502145C1D75E5B90A72DC.mlw
sha1: 4415587a9802a1235bce6261005585393951b30e
sha256: 508324c01d5389e04f51201bada16425da4972ed1906bc402b5d2f873b714fee
sha512: 64c63f4e20ae4577b6ccfa651f6055463d6d88b824e98eb489908ef1fa9bcdb710e25600bb250d5510f7516c660b6cc3ce04a1a7956b4683c4888ca7196869ca
ssdeep: 3072:heMvNIASOiGHpJlz9y+mS1VqZUV1EPcEiiSZwdXd0S2I6X:3ixGJJd9pX1gUAP16w2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2006-2012 - RescoSoft Tech.
InternalName: profctl
FileVersion: 6.4.2.3
CompanyName: RescoSoft Tech.
ProductName: Profiler Runtime Control
ProductVersion: 6.4.2.3
FileDescription: Profiler Runtime Control
OriginalFilename: profctl
Translation: 0x0009 0x04b0

Win32/Kryptik.AWTJ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.3944
CynetMalicious (score: 100)
ALYacTrojan.Autoruns.GenericKDS.44502826
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.6afc50
SymantecTrojan.Ransomlock.Q
ESET-NOD32a variant of Win32/Kryptik.AWTJ
APEXMalicious
AvastWin32:LockScreen-TB [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Autoruns.GenericKDS.44502826
NANO-AntivirusTrojan.Win32.RiskGen.bmjyjc
MicroWorld-eScanTrojan.Autoruns.GenericKDS.44502826
TencentWin32.Trojan.Foreign.dctd
Ad-AwareTrojan.Autoruns.GenericKDS.44502826
SophosMal/Generic-R + Mal/Ransom-AL
ComodoMalware@#1y1nmk48qghaa
BitDefenderThetaGen:NN.ZexaF.34678.iq0@aePNJthk
VIPRETrojan.Win32.Reveton.b!ag (v)
TrendMicroTROJ_SPNR.14CO13
McAfee-GW-EditionPWS-Zbot-FALP!D5312FB6AFC5
FireEyeGeneric.mg.d5312fb6afc50214
EmsisoftTrojan.Autoruns.GenericKDS.44502826 (B)
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1113270
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Urausy.C
ArcabitTrojan.Autoruns.GenericS.D2A70F2A
AegisLabTrojan.Win32.Foreign.j!c
GDataTrojan.Autoruns.GenericKDS.44502826
McAfeePWS-Zbot-FALP!D5312FB6AFC5
MAXmalware (ai score=84)
VBA32BScope.TrojanRansom.Foreign
PandaTrj/OCJ.D
TrendMicro-HouseCallTROJ_SPNR.14CO13
RisingRansom.Urausy!8.2B7 (CLOUD)
YandexTrojan.GenAsa!ZV5Xcttofl0
IkarusTrojan.ScreenLocker
FortinetW32/Foreign.AREK!tr
AVGWin32:LockScreen-TB [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.AWTJ?

Win32/Kryptik.AWTJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment