Malware

Win32/Kryptik.AAAB information

Malware Removal

The Win32/Kryptik.AAAB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AAAB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.AAAB?


File Info:

crc32: 772CAD7C
md5: 1d7d9dd6e5e6444e003282d3b49f7d53
name: 1D7D9DD6E5E6444E003282D3B49F7D53.mlw
sha1: b71a9deab476393c70f2aff757b05badb04af4a4
sha256: 4ff3f5f7bf6aacab1951b03f3833c65ce83402ad50f9d30c58f17d2e3fc073cc
sha512: 830b81e38c02b9018d692987322956f4e68685531d4d680323334def2d29fd48b84cae010badac48684486444224724880eba8a8bcb2499ea1e5af898efe8883
ssdeep: 768:iw90yTKWbpx9Q6uMR4cmUIAEozpL4EGRNn+rM:iwlPp/Q6PR8Yzl0EIn+rM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 Cakes Cite 1995-2009
InternalName: Cuff
FileVersion: 5.9
CompanyName: Doctor Laura Tidy Side
ProductName: Stomp Safes Sag Crows
ProductVersion: 5.9
FileDescription: Put Quiz Alias Chaos
OriginalFilename: Mates.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.AAAB also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Winlock.4142
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Dofoil.A
ALYacGen:Variant.Barys.665
CylanceUnsafe
ZillyaTrojan.PornoAsset.Win32.634
SangforSuspicious.Win32.Barys.665
AlibabaRansom:Win32/PornoAsset.f66e8c5d
Cybereasonmalicious.6e5e64
CyrenW32/Yakes.B.gen!Eldorado
SymantecPacked.Generic.340
ESET-NOD32a variant of Win32/Kryptik.AAAB
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Pornoasset-626
KasperskyTrojan-Ransom.Win32.PornoAsset.azo
BitDefenderGen:Variant.Barys.665
NANO-AntivirusTrojan.Win32.Winlock.fjphk
MicroWorld-eScanGen:Variant.Barys.665
TencentWin32.Trojan.Pornoasset.lej
Ad-AwareGen:Variant.Barys.665
SophosML/PE-A + Mal/EncPk-AAI
ComodoSuspicious@#1kh7pml9ljzp4
BitDefenderThetaGen:NN.ZexaF.34692.bmKfaal0UUii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansom-AG
FireEyeGeneric.mg.1d7d9dd6e5e6444e
EmsisoftGen:Variant.Barys.665 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PornoAsset.ty
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_77%
Antiy-AVLTrojan/Generic.ASMalwS.752CAA
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Trasbind.A
ArcabitTrojan.Barys.665
AegisLabTrojan.Win32.Monder.l6UV
GDataGen:Variant.Barys.665
AhnLab-V3Trojan/Win32.Ransomlock.R11621
McAfeeArtemis!1D7D9DD6E5E6
MAXmalware (ai score=100)
VBA32BScope.Trojan-Ransom.Winlock.7921
PandaGeneric Malware
RisingRansom.Trasbind!8.292E (CLOUD)
YandexTrojan.Kryptik!I5FyHmrb/UI
IkarusTrojan-Ransom.PornoAsset
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Yakes.B!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.AAAB?

Win32/Kryptik.AAAB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment