Malware

Win32/Packed.Asprotect.KJ (file analysis)

Malware Removal

The Win32/Packed.Asprotect.KJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Asprotect.KJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Raccoon malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

t.me

How to determine Win32/Packed.Asprotect.KJ?


File Info:

name: 0A55237224259B6EB5B6.mlw
path: /opt/CAPEv2/storage/binaries/793f7b1dc6181c8f24467d1fdd5e414a0f047b98f3572166b2cf3fef37f71325
crc32: 2E06DC63
md5: 0a55237224259b6eb5b62ac8d0dfa114
sha1: 8dfd7cb3777ae524c0056cbaa35da9b0b0ba2ab4
sha256: 793f7b1dc6181c8f24467d1fdd5e414a0f047b98f3572166b2cf3fef37f71325
sha512: f99b6e0fe4c51021932c2fa2604c9c350c09614b51f8d59e5c8d3dcba0bf771e9c04a39d1b0489a891560244d26b2e46e05a2ea574a22ccf72b1db4417b16474
ssdeep: 24576:rkAiwjMz917BXD9hnxG3UHDPt5b5OCCm/AV/fjTC8J7oZnRwlfb:QAI9BBXD9hnxnJ5b5OfnN7oHGT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB352392C34100B5DA628334CF734B4CA6365DEE5D90AF976ACAF4683FF5B734826608
sha3_384: 52bf31d01e6b616a0e2fa99e9d1f42e9bb6cd1651ba4e1efe508d775d9e8269fa4851e6cc93b41d2bd37e6fa0dd4ac7f
ep_bytes: 6801404e00e801000000c3c3b7700626
timestamp: 2021-11-22 21:39:44

Version Info:

0: [No Data]

Win32/Packed.Asprotect.KJ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Convagent.i!c
DrWebTrojan.PWS.Stealer.31482
MicroWorld-eScanTrojan.GenericKD.38101314
FireEyeGeneric.mg.0a55237224259b6e
CAT-QuickHealTrojanpws.Racealer
ALYacTrojan.GenericKD.38101314
CylanceUnsafe
SangforInfostealer.Win32.Convagent.gen
K7AntiVirusTrojan ( 0058acee1 )
AlibabaTrojanPSW:Win32/Racealer.d3626c53
K7GWTrojan ( 0058acee1 )
Cybereasonmalicious.3777ae
BitDefenderThetaGen:NN.ZexaF.34062.eHWaa07XCRli
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Asprotect.KJ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Racealer.mqi
BitDefenderTrojan.GenericKD.38101314
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.38101314
EmsisoftTrojan.GenericKD.38101314 (B)
TrendMicroTROJ_GEN.R011C0WKQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
IkarusTrojan.Win32.ASProtect
GDataTrojan.GenericKD.38101314
AviraTR/AD.StellarStealer.hjspf
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Racealer.1116672
MicrosoftTrojan:Win32/CryptInject!MSR
CynetMalicious (score: 100)
McAfeeArtemis!0A5523722425
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Racealer
MalwarebytesSpyware.RaccoonStealer
TrendMicro-HouseCallTROJ_GEN.R011C0WKQ21
YandexTrojan.PWS.Racealer!DRGV9eXGpno
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Packed.Asprotect.KJ?

Win32/Packed.Asprotect.KJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment