Trojan

Should I remove “Trojan.Ciusky.CryptedAit.1”?

Malware Removal

The Trojan.Ciusky.CryptedAit.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ciusky.CryptedAit.1 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Trojan.Ciusky.CryptedAit.1?


File Info:

crc32: EA238046
md5: a79192808f19e3f4b4ed7d48983684f3
name: A79192808F19E3F4B4ED7D48983684F3.mlw
sha1: 668acc37f1aadcbea568acf4055d00ced32ecf3d
sha256: 8f4ec0f164657fae38d4555a0f710ddc67b9e421ac0d7c82491c30a51895031d
sha512: fe11cd21907aecdde93ea4c5361d2d25c307ef71bb00e8d32c94dabbb780a6e58e068facdf0c3e2fc7efc460f85d3f2144734fc1e882ffdd0d5cfff85696a175
ssdeep: 24576:BAOcZpJO36E6Pe7+UlKPEqU65ulTqo9/s0Y5a+nzQ:bRf627+daz9002/nk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Ciusky.CryptedAit.1 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005734f51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojandropper.Generic
ALYacTrojan.GenericKD.36862173
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 005734f51 )
Cybereasonmalicious.08f19e
CyrenW32/Trojan.ODRX-0142
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DE
ZonerProbably Heur.RARAutorun
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Nanocore-9406023-1
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.Ciusky.CryptedAit.1
ViRobotTrojan.Win32.Z.Nanocore.1037491
MicroWorld-eScanTrojan.Ciusky.CryptedAit.1
TencentWin32.Trojan-dropper.Generic.Lnnt
SophosML/PE-A + Mal/MalitRar-I
TrendMicroTROJ_GEN.R002C0PE821
McAfee-GW-EditionBehavesLike.Win32.Suspicioustrojan.fc
FireEyeGeneric.mg.a79192808f19e3f4
AviraTR/Agent.ugcvl
eGambitUnsafe.AI_Score_83%
MicrosoftTrojan:Win32/Nanocore.BA!MTB
GridinsoftRansom.Win32.Wacatac.oa!s1
AegisLabTrojan.Win32.Generic.b!c
ZoneAlarmHEUR:Trojan-Dropper.Win32.Generic
GDataTrojan.GenericKD.36862173
AhnLab-V3Trojan/Win.Generic.R416039
McAfeeArtemis!A79192808F19
MAXmalware (ai score=81)
VBA32Trojan.AgentTesla
MalwarebytesTrojan.Dropper.SFX.Generic
TrendMicro-HouseCallTROJ_GEN.R002C0PE821
RisingTrojan.AgentTesla!8.104D5 (CLOUD)
IkarusTrojan-Spy.FormBook
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Ciusky.CryptedAit.1?

Trojan.Ciusky.CryptedAit.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment