Trojan

Trojan.Win32.Cryprar.yy (file analysis)

Malware Removal

The Trojan.Win32.Cryprar.yy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.yy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.yy?


File Info:

name: 31EE443901F7AD398123.mlw
path: /opt/CAPEv2/storage/binaries/ee2252905985d8871e455936bd59d031903e3b85149f3339ab6195d7e4befe2a
crc32: AA2BAC1C
md5: 31ee443901f7ad398123d09936e5c04f
sha1: 092f96a87e02a24ce569a70ac208ffb71494f547
sha256: ee2252905985d8871e455936bd59d031903e3b85149f3339ab6195d7e4befe2a
sha512: 8e5cde13975b8608e397b07a909cda8efd17b6d7d0d469e54f739b5d32443799e7d996e3c41eb34f8907e19e2943bc6cb2bb2d0c501a56e22611c4168d814396
ssdeep: 24576:8qIDJtORjn+whBfJXAENLSHOHKxvQkw0zDahyLRZMFbRz6IDPvnWUSEFNsFX6A+G:8VORjZhBfJXAE9cOHWvtw0kyvObl6kPG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1806523027FC0D9B1D6725C325BB59B74283E7E216F91EECFA3944A2ED8305C09726762
sha3_384: 846c59e1f767335501f22c17f4c599f3ca435fc8d70452da47a138e0eee25f41a4370a093f6a681006aac9e3bc5f05e5
ep_bytes: e846050000e978feffffcccccccccccc
timestamp: 2021-11-15 10:52:31

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 6.10.2
ProductVersion: 6.10.2
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2021
OriginalFilename: WinRAR.exe
Translation: 0x0409 0x04e4

Trojan.Win32.Cryprar.yy also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Cryprar.4!c
MicroWorld-eScanTrojan.Ciusky.Gen.6
FireEyeGeneric.mg.31ee443901f7ad39
McAfeeArtemis!31EE443901F7
CylanceUnsafe
K7AntiVirusTrojan ( 0058245c1 )
AlibabaTrojan:Win32/Cryprar.a7e3ab2b
K7GWTrojan ( 0058245c1 )
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DQ
APEXMalicious
AvastSFX:Runner-C [Bd]
KasperskyTrojan.Win32.Cryprar.yy
BitDefenderTrojan.Ciusky.Gen.6
TencentWin32.Trojan.Cryprar.Lkoc
Ad-AwareTrojan.Ciusky.Gen.6
SophosMal/Generic-S
DrWebTrojan.MulDrop19.11822
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
EmsisoftTrojan.Ciusky.Gen.6 (B)
Paloaltogeneric.ml
GDataTrojan.Ciusky.Gen.6
AviraTR/Agent.kwito
Antiy-AVLTrojan/Win32.Generic
ArcabitTrojan.Ciusky.Gen.6
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Runner.C4814559
VBA32BScope.Trojan.Meterpreter
ALYacTrojan.Ciusky.Gen.6
MalwarebytesTrojan.Dropper.SFX
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0CL521
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
IkarusTrojan.Agent
AVGSFX:Runner-C [Bd]
Cybereasonmalicious.901f7a
PandaTrj/CI.A

How to remove Trojan.Win32.Cryprar.yy?

Trojan.Win32.Cryprar.yy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment