Malware

AutoIt:Kryptik-E [Trj] malicious file

Malware Removal

The AutoIt:Kryptik-E [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AutoIt:Kryptik-E [Trj] virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine AutoIt:Kryptik-E [Trj]?


File Info:

crc32: 9FB2D57B
md5: f7cf63016d680d30db9dccbc385489aa
name: F7CF63016D680D30DB9DCCBC385489AA.mlw
sha1: 311b241d664039aa0b3b2446a83eeda9bfef953a
sha256: dda89046fb597c1a278580c206fa7ca5a28181f9bee103e0b4dffc0c8fd86fad
sha512: 3a85edaca78f390757de8d603bfc815d60361bbc808f5bd976efa4cd50e07f2786b80f4e7e4db4d8f97ef6d032310a6b57fa66ce3248ceddf4d3f8fa13940c0e
ssdeep: 12288:fozGdX0M4ornOmZIzfMwHHQmRROXKDdyyzbtlzJJr+qGIx7v9JxbU6M:f4GHnhIzOaD1l+qGIx7v9Jx4L
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

AutoIt:Kryptik-E [Trj] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.4587922
FireEyeGeneric.mg.f7cf63016d680d30
ALYacTrojan.GenericKD.4587922
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005642691 )
BitDefenderTrojan.GenericKD.4587922
K7GWTrojan ( 005642691 )
Cybereasonmalicious.16d680
BitDefenderThetaAI:Packer.A472CF5015
CyrenW32/AutoIt.SR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastAutoIt:Kryptik-E [Trj]
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareTrojan.GenericKD.4587922
SophosMal/Generic-S
ComodoMalware@#md2mul4zr670
F-SecureDropper.DR/AutoIt.Gen8
BaiduAutoIt.Trojan.Injector.bs
ZillyaTrojan.Injector.Win32.502309
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.jc
EmsisoftTrojan.GenericKD.4587922 (B)
AviraDR/AutoIt.Gen8
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Dynamer!rfn
ArcabitTrojan.Generic.D460192
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.4587922
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C1854676
McAfeeArtemis!F7CF63016D68
MalwarebytesMalware.AI.4228984958
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.CQJ
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_85%
FortinetW32/Injector.CQJ!tr
AVGAutoIt:Kryptik-E [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove AutoIt:Kryptik-E [Trj]?

AutoIt:Kryptik-E [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment