Malware

Win32/Kryptik.BJKK removal

Malware Removal

The Win32/Kryptik.BJKK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BJKK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.BJKK?


File Info:

name: C7DDA0FB6AA34EA203D0.mlw
path: /opt/CAPEv2/storage/binaries/4f18adbb1aced902e6040ad553030be6fdc7e9eb707688ca1c55a9a9c009a07d
crc32: 10A2A0AD
md5: c7dda0fb6aa34ea203d0c74e0455f658
sha1: 77b4cdc9aab8381317c8364e067044b092dcf5d8
sha256: 4f18adbb1aced902e6040ad553030be6fdc7e9eb707688ca1c55a9a9c009a07d
sha512: 1a29f3959b92d072a0648d580e8fa98a441fd1de07f48284b6ef1a530eac586827997aac69d305e304200dc77c3836907bb61a83c147b622a0fd6a93bc67f016
ssdeep: 3072:vbJ8MJJ/pZ22HPc+Q0j40UvWw48ddLM6hMLIokjwrhpcSvMRmT:d5XG20ka48ddLM6njNSJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15F249C33FA0ECCF1C55F40BA14C695AE0585816A85DF6753D0D85A62FCCAE5A38EB80F
sha3_384: cbff92102fb6b9f93eebab337672e3c1e577bb894ee29223d6892f8d2d69e7ddd664025e1e3b9ba9a9acdfa6893f4c4f
ep_bytes: 558bec81ec180200008b4d08890dc46b
timestamp: 2013-08-31 06:06:17

Version Info:

CompanyName: Корпорация М айкрософт
FileDescription: Диспетчер синхронизации
FileVersion: 5.1.2600.5512 (xpsp.080413-2108)
Translation: 0x0419 0x04b0

Win32/Kryptik.BJKK also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.94551
ClamAVWin.Trojan.Generickd-259
FireEyeGeneric.mg.c7dda0fb6aa34ea2
McAfeeGenericRXFT-IY!C7DDA0FB6AA3
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Kryptik.Win32.410232
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005223351 )
K7GWTrojan ( 005223351 )
Cybereasonmalicious.b6aa34
BaiduWin32.Trojan.Kryptik.ac
VirITTrojan.Win32.Crypt2.AZEL
CyrenW32/Agent.BCI.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BJKK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.94551
NANO-AntivirusTrojan.Win32.Mods.cqiula
AvastWin32:ZAccess-TL [Trj]
TencentTrojan.Win32.ShipUp.a
EmsisoftTrojan.GenericKDZ.94551 (B)
F-SecureTrojan.TR/Crypt.ASPM.Gen
DrWebTrojan.Mods.1
VIPRETrojan.GenericKDZ.94551
TrendMicroTROJ_KRYPTK.SML2
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
Trapminemalicious.high.ml.score
SophosTroj/Agent-ADXT
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.94551
JiangminTrojan/ShipUp.wf
AviraTR/Crypt.ASPM.Gen
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Gepys.AA@522ik2
ArcabitTrojan.Generic.D17157
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Zbot.SIBL!MTB
GoogleDetected
AhnLab-V3Backdoor/Win.ZAccess.R574154
Acronissuspicious
VBA32BScope.Malware-Cryptor.Hlux
ALYacTrojan.GenericKDZ.94551
MAXmalware (ai score=87)
Cylanceunsafe
TrendMicro-HouseCallTROJ_KRYPTK.SML2
RisingTrojan.Kryptik!1.A898 (CLASSIC)
YandexTrojan.GenAsa!XPxORjhn1zY
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.ShipUp.gen
FortinetW32/Kryptik.HIJR!tr
BitDefenderThetaGen:NN.ZexaF.36164.nK1@aOEQ31nc
AVGWin32:ZAccess-TL [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.BJKK?

Win32/Kryptik.BJKK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment