Malware

Win32/Kryptik.JSA removal instruction

Malware Removal

The Win32/Kryptik.JSA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.JSA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.JSA?


File Info:

name: 6F88C050B3055E9358C1.mlw
path: /opt/CAPEv2/storage/binaries/8cdda9b5a647ee9991963bacbc106e5cc3a56fa7cf506b2feffd870cfa69ce1c
crc32: 7E95D867
md5: 6f88c050b3055e9358c1b6c6a41bfd0c
sha1: 4acd84d1541bfb4545d2c8039bba8b865d36f1ef
sha256: 8cdda9b5a647ee9991963bacbc106e5cc3a56fa7cf506b2feffd870cfa69ce1c
sha512: 21a1ffd81ac3e16cac036f58a8ba94d3d96e8b2ec8d59f5cf37c8088bccba131464c30596cad04bc985809f137b99e5361929734cb958d974879255221d568c3
ssdeep: 3072:DpnVc5BaxJRXUCf+usIfkU/GP5fMFstAE0ISbqV:D/cG3XJ2uLkU+xMdE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AE3124DE39ADF81D5391A3CBD82920892C3BE2B59F64299B841324DF433D35E22F795
sha3_384: 873f5c577c4ea52ac2a0377cad00eacf7847208cc0ae59d9748f4c2b25d7b4dbb8c77a229e834ef0c543f3f998a4ad66
ep_bytes: 60be004041008dbe00d0feff57eb0b90
timestamp: 2008-01-01 06:19:04

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: Antivirus Control Center
FileVersion: 8.00.70.08
InternalName: Control Center
LegalCopyright: Copyright © 2008 Avira GmbH. All rights reserved.
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
OriginalFilename: avcenter.exe
PrivateBuild:
ProductName: AntiVir Workstation
ProductVersion: 8.00.70.08
SpecialBuild:
Translation: 0x0800 0x04b0

Win32/Kryptik.JSA also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.SpyEyes.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.6f88c050b3055e93
CAT-QuickHealTrojanBNK.Zbot.mue
ALYacGen:Heur.VIZ.2
CylanceUnsafe
ZillyaTrojan.SpyEyes.Win32.1978
SangforTrojan.Win32.Kryptik.JSA
K7AntiVirusTrojan ( 004af95c1 )
AlibabaTrojanSpy:Win32/SpyEyes.38004ca9
K7GWTrojan ( 004af95c1 )
Cybereasonmalicious.0b3055
BitDefenderThetaGen:NN.ZexaF.34212.imKfaKfR6qgc
VirITTrojan.Win32.Generic.AOQN
CyrenW32/S-5f8a72a3!Eldorado
SymantecTrojan.Spyeye
ESET-NOD32a variant of Win32/Kryptik.JSA
TrendMicro-HouseCallTROJ_CRYPTR.SMAX
ClamAVWin.Trojan.Agent-433116
KasperskyTrojan-Spy.Win32.SpyEyes.euk
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.ZBot.dcgsk
MicroWorld-eScanGen:Heur.VIZ.2
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Spyeyes.Wskm
Ad-AwareGen:Heur.VIZ.2
EmsisoftGen:Heur.VIZ.2 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
DrWebTrojan.PWS.Panda.452
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroTROJ_CRYPTR.SMAX
McAfee-GW-EditionPWS-Spyeye.fa
SophosMal/Generic-R + Mal/FakeAV-BW
APEXMalicious
GDataGen:Heur.VIZ.2
JiangminTrojanSpy.SpyEyes.oss
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.187C652
ArcabitTrojan.VIZ.2
ZoneAlarmTrojan-Spy.Win32.SpyEyes.euk
MicrosoftPWS:Win32/Zbot
SentinelOneStatic AI – Malicious PE
AhnLab-V3Spyware/Win32.Zbot.R2551
McAfeeArtemis!6F88C050B305
TACHYONTrojan-Spy/W32.SpyEyes.164352.G
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
RisingSpyware.SpyEyes!8.4AA (CLOUD)
YandexTrojan.Kryptik!Vu6Icrw+EjE
IkarusTrojan.Win32.Spyeye
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Kryptik.JSA?

Win32/Kryptik.JSA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment