Malware

Troj/Krypt-CY removal

Malware Removal

The Troj/Krypt-CY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Krypt-CY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Hungarian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

boombangers00666999.sc

How to determine Troj/Krypt-CY?


File Info:

crc32: 74F3123B
md5: 91138161b4ae70a1a5bf5e1070f6e369
name: 91138161B4AE70A1A5BF5E1070F6E369.mlw
sha1: d6d2a62e08c359431ec4c4410b9f7ad0c820f65f
sha256: 45b4cad3196d118a9bd4da2e67d16d678ef829748a42df2f144a6ea32a71d45f
sha512: ce828c555b68069f6730ba4d9e1a7dde77a05fd955181eed2278fb1d3cb25830ee6b7d2705d60447e43b0e8df2df72bcb71d3607f16e1a2a182a6024583fc534
ssdeep: 6144:t5e34Pa/InteZqJL6yxOOhxxdeTr/ekI:TzDtPL60zxd6L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sajbmianozu.iya
ProductVersion: 8.64.59.5
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0527 0x007a

Troj/Krypt-CY also known as:

ALYacTrojan.GenericKD.47087760
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0058838d1 )
K7AntiVirusTrojan ( 0058838d1 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMRX
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.47087760
MicroWorld-eScanTrojan.GenericKD.47087760
Ad-AwareTrojan.GenericKD.47087760
SophosTroj/Krypt-CY
BitDefenderThetaGen:NN.ZexaF.34170.sq0@ayZA8xbO
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dh
FireEyeGeneric.mg.91138161b4ae70a1
EmsisoftTrojan.GenericKD.47087760 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Tofsee.evu
eGambitUnsafe.AI_Score_98%
MicrosoftRansom:Win32/StopCrypt.SL!MTB
GDataTrojan.GenericKD.47087760
AhnLab-V3Infostealer/Win.SmokeLoader.R443617
Acronissuspicious
McAfeePacked-GDT!91138161B4AE
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.95 (RDMK:JJVvy3AiYws9UUOSbR7j3Q)
IkarusTrojan-Banker.UrSnif
FortinetW32/GenKryptik.FLKL!tr
AVGWin32:PWSX-gen [Trj]

How to remove Troj/Krypt-CY?

Troj/Krypt-CY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment