Malware

Win32/Kryptik.CLKJ removal tips

Malware Removal

The Win32/Kryptik.CLKJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.CLKJ virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.CLKJ?


File Info:

name: 2598C42AD835EC2E7054.mlw
path: /opt/CAPEv2/storage/binaries/2dc5060439bfa0787228932f773791d2b5219cd59d0c3e0841af8b45135580bf
crc32: 18A67231
md5: 2598c42ad835ec2e70543ed3854c107d
sha1: cff2d5be0e0f94cf252d5c979750f036be04be14
sha256: 2dc5060439bfa0787228932f773791d2b5219cd59d0c3e0841af8b45135580bf
sha512: 2fdd0daceb17af55f46b1d8f4c905ade1accbe7011646a4d194c22304370c78619ed11a32ff6162cea3d5d0f94775c426d50210ada8530e7eb5c2922d188dd3e
ssdeep: 384:DbbkrRWSjubh9bJHupySeNvt0WzMudtoUKc:Dbbkrtju1uOdt48KUKc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F6E25F346FD61AB9F323DEB24AF2D6876635BD31A462420F80107B324833DB19B5DDA5
sha3_384: 6c50cf28a121532665265e2be171a810a3ff31e2472635a5f86f560ab5fcced858accb1cead44b6bdab55621e8e8fa94
ep_bytes: 60be009040008dbe0080ffff57eb0b90
timestamp: 1973-03-04 21:38:58

Version Info:

CompanyName: Landed
FileDescription: Landed company
FileVersion: Version 1.1.16
InternalName: Landed
LegalCopyright: Copyright by Landed
OriginalFilename: Landed
Translation: 0x0408 0x04e3

Win32/Kryptik.CLKJ also known as:

BkavW32.AIDetectMalware
AVGWin32:Downloader-WIH [Trj]
tehtrisGeneric.Malware
DrWebTrojan.Upatre.10623
MicroWorld-eScanTrojan.Spy.Zbot.FND
FireEyeGeneric.mg.2598c42ad835ec2e
CAT-QuickHealDownldr.Upatre.S535438
SkyhighBehavesLike.Win32.PWSZbot.nm
ALYacTrojan.Spy.Zbot.FND
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Upatre.Win32.5759
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanDownloader:Win32/Upatre.e4878ff5
K7GWTrojan-Downloader ( 0055c6c71 )
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
BitDefenderThetaGen:NN.ZexaF.36802.bmMfambz5bjG
SymantecDownloader.Upatre!gen5
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.CLKJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Generic-6335766-0
KasperskyTrojan-Downloader.Win32.Upatre.fxzr
BitDefenderTrojan.Spy.Zbot.FND
NANO-AntivirusTrojan.Win32.MlwGen.dffywr
AvastWin32:Downloader-WIH [Trj]
TencentMalware.Win32.Gencirc.10bfc0fb
EmsisoftTrojan.Spy.Zbot.FND (B)
F-SecureHeuristic.HEUR/AGEN.1314970
BaiduWin32.Trojan-Downloader.Waski.a
VIPRETrojan.Spy.Zbot.FND
SophosTroj/HkMain-AZ
IkarusVirTool.Obfuscator
JiangminHoax.ArchSMS.aipg
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraHEUR/AGEN.1314970
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.b.972
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
ArcabitTrojan.Spy.Zbot.FND
ZoneAlarmTrojan-Downloader.Win32.Upatre.fxzr
GDataWin32.Trojan-Downloader.Upatre.BK
VaristW32/Trojan.PWRR-1138
AhnLab-V3Downloader/Win.Upatre.R638811
Acronissuspicious
McAfeeArtemis!2598C42AD835
VBA32BScope.TrojanDownloader.Upatre
Cylanceunsafe
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!wyngdUsBDpY
MAXmalware (ai score=84)
MaxSecureTrojan.Upatre.Gen
FortinetW32/Agent.PXO!tr.dldr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/PWSZbot.GSB!MTB

How to remove Win32/Kryptik.CLKJ?

Win32/Kryptik.CLKJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment