Malware

About “Win32/Kryptik.EIJB” infection

Malware Removal

The Win32/Kryptik.EIJB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EIJB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.EIJB?


File Info:

name: 2457FD90FC39062DA955.mlw
path: /opt/CAPEv2/storage/binaries/12d2925b532a306139a780c2df774fade2456c61355c4a2d1374d2c4c66fe4b7
crc32: 18B639D8
md5: 2457fd90fc39062da9555cf3358b07c4
sha1: 219fa5f3dba66b1aa0ed62e6af22940f410835c2
sha256: 12d2925b532a306139a780c2df774fade2456c61355c4a2d1374d2c4c66fe4b7
sha512: 84c7b6e68e6da227a7ac3223edb0c186d1b8db8fd2f77cb16b8cdf90527dd956f1005ab54d5e2eccf798f4cdfdc883d5de6952ad9be2e80dcebf16ad9b5994ad
ssdeep: 6144:RSvB+Lw0c+m7bsstkz9rytffoRBRYwPtog2dd0etWSwj:R+ALmbssOzItOWwloj70Swj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BC240127FCA8082FEE779B31DAF9E127C718E2F59B4094D38859481965D7BD2A2B010D
sha3_384: 96fb150b33a82300eb03932bd12f5787f0d94d37d5151cfe908c594ff4f6e42e944ae82eb1bf4fa6b448b9e6e579ce40
ep_bytes: 558bec83c4c433c9518b3dff84400081
timestamp: 2012-10-05 15:24:46

Version Info:

CompanyName: Trend Micro
FileVersion: 2.3.2.3
ProductVersion: 6.3.7.4
Translation: 0x0409 0x0000

Win32/Kryptik.EIJB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.lZlP
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Pack.Emotet.2
FireEyeGeneric.mg.2457fd90fc39062d
McAfeePWSZbot-FACG!2457FD90FC39
CylanceUnsafe
VIPREGen:Heur.Pack.Emotet.2
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.0fc390
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.EIJB
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Zbot.tscc
BitDefenderGen:Heur.Pack.Emotet.2
NANO-AntivirusTrojan.Win32.Zbot.denhkc
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan-spy.Zbot.Hpid
Ad-AwareGen:Heur.Pack.Emotet.2
EmsisoftGen:Heur.Pack.Emotet.2 (B)
ComodoMalware@#2njbb3lg6qli9
DrWebTrojan.PWS.Panda.2401
ZillyaTrojan.Kryptik.Win32.3877827
TrendMicroTROJ_SPNR.0BJA14
McAfee-GW-EditionPWSZbot-FACG!2457FD90FC39
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Spy.Zbot.CE
JiangminTrojanSpy.Zbot.fegc
GoogleDetected
AviraHEUR/AGEN.1250244
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Zbot.ts.(kcloud)
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34606.nu2@a4JYYGni
ALYacGen:Heur.Pack.Emotet.2
MAXmalware (ai score=84)
MalwarebytesMalware.Heuristic.1006
TrendMicro-HouseCallTROJ_SPNR.0BJA14
RisingTrojan.Dynamer!8.3A0 (TFE:3:3E2wWOwzFKQ)
YandexTrojanSpy.Zbot!ozTjoutmBs4
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Evo-gen [Trj]
PandaTrj/Chgt.C
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.EIJB?

Win32/Kryptik.EIJB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment