Malware

Win32/Kryptik.EJTN removal guide

Malware Removal

The Win32/Kryptik.EJTN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EJTN virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Connects to Tor Hidden Services through a Tor gateway
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io
detoxnewjersey.com
ezglobalmarketing.com
www.hugedomains.com
ocsp.digicert.com
fgainterests.com
fisherfab.com
www.afternic.com
ocsp.godaddy.com
ledshoppen.nl
lightblueworld.com
crl.godaddy.com
www.lightblueworld.com
zpr5huq4bgmutfnf.onion.to
zpr5huq4bgmutfnf.tor2web.org

How to determine Win32/Kryptik.EJTN?


File Info:

crc32: 35062E38
md5: 1265432c16ea20e672afecb20ddaed3d
name: 1265432C16EA20E672AFECB20DDAED3D.mlw
sha1: 885c903fbaf64068c2c3a46b0428e50f05accbc7
sha256: f4568fb566f28c9205bb7feddc44e02515b8beac33de12ea8b85056ea7ea8978
sha512: 09956ee9fbd0b33aadd4965f334ca81c652cd6426a4384542d8b1a23e3761997ff5ffa2d631f5bf112445efc3172b868b7363592bb18d3e62161044c405d05de
ssdeep: 6144:JhYi5hsl3VNaieNtwCLmfwcDYdJyDMOSR:JhDk2ioSEcEHb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Marketability 1991-2000
InternalName: Redisplay.exe
FileVersion: 7.5.4.6
CompanyName: Johnny Lee
ProductName: Rebuttals
ProductVersion: 7.5.4.6
FileDescription: Lop
OriginalFilename: Redisplay.exe
Translation: 0x0409 0x04e8

Win32/Kryptik.EJTN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055dd191 )
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.37547
CynetMalicious (score: 100)
CAT-QuickHealRansom.Tescrypt.MUE.A4
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.764886
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Kryptik.235faa57
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.c16ea2
BaiduWin32.Trojan.Kryptik.ov
CyrenW32/S-06ce04bd!Eldorado
SymantecRansom.TeslaCrypt!gm
ESET-NOD32a variant of Win32/Kryptik.EJTN
APEXMalicious
AvastWin32:TeslaCrypt-C [Trj]
ClamAVWin.Trojan.Agent-1349616
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.MlwGen.duxmdi
ViRobotTrojan.Win32.U.Agent.249856.A
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.10b1f425
Ad-AwareTrojan.Cripack.Gen.1
SophosMal/Generic-R + Mal/Tinba-N
ComodoTrojWare.Win32.Ransom.Tescrypt.A@5y3pim
BitDefenderThetaGen:NN.ZexaF.34692.pq0@aKrSeNki
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103BO20
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.1265432c16ea20e6
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dwilp
WebrootTrojan.Dropper.Gen
AviraTR/Tescrypt.bge
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.13402F8
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Tescrypt.A
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Cripack.Gen.1
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeTeslaCrypt!1265432C16EA
MAXmalware (ai score=99)
VBA32Trojan.Deshacop
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103BO20
RisingTrojan.Kryptik!1.A1D1 (CLOUD)
YandexTrojan.Deshacop!y8SXq9h67bo
IkarusTrojan.Win32.Deshacop
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.DTBC!tr
AVGWin32:TeslaCrypt-C [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.EJTN?

Win32/Kryptik.EJTN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment