Malware

Should I remove “Win32/Kryptik.AAUK”?

Malware Removal

The Win32/Kryptik.AAUK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AAUK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates Zeus (Banking Trojan) mutexes
  • Zeus P2P (Banking Trojan)
  • Attempts to modify browser security settings
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.AAUK?


File Info:

crc32: 76389584
md5: 60b1653c9db0a802536a373e0260b437
name: 60B1653C9DB0A802536A373E0260B437.mlw
sha1: f315fb2917046504bbe84767d4a7bfee3b07f54d
sha256: 248e2cbfafe7096949e2a98b32b7a6a1eab6cc6ecd25b368871cc176179942ca
sha512: f49c8bcc542a203200116d53e73bfc859f60509a59220a462d5523a0c3553317fb145ec6cead5a583e6d67ef281db21647ae399ac8573c89416d3a9604d410b5
ssdeep: 6144:QESwJqJJn+SSz8lJ24kjJ9Tohey80IJ7JbaFdJLJiaiJ9VJ2yJJuqRk4JUCJzzb:htRPD2Aq/ByScs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.AAUK also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0033aca51 )
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.10316
CynetMalicious (score: 100)
ALYacGen:Variant.Barys.54523
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.125614
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Kryptik.e5281db2
K7GWTrojan ( 0033aca51 )
Cybereasonmalicious.c9db0a
BaiduWin32.Trojan.Kryptik.afd
CyrenW32/Zbot.CK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AAUK
APEXMalicious
AvastWin32:MalOb-ID [Cryp]
ClamAVWin.Trojan.Kazy-1786
KasperskyTrojan-Spy.Win32.Zbot.czco
BitDefenderGen:Variant.Barys.54523
NANO-AntivirusTrojan.Win32.Zbot.echhua
MicroWorld-eScanGen:Variant.Barys.54523
TencentWin32.Trojan-spy.Zbot.Wnwb
Ad-AwareGen:Variant.Barys.54523
SophosML/PE-A + Mal/EncPk-ABZ
ComodoTrojWare.Win32.Kryptik.XVV@4lo2v3
F-SecureTrojan.TR/Spy.Zbot.czcob
BitDefenderThetaGen:NN.ZexaF.34266.RJW@aye@uEb
VIPRETrojan.Win32.EncPk.gen.abz (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.wz
FireEyeGeneric.mg.60b1653c9db0a802
EmsisoftGen:Variant.Barys.54523 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Zbot.czcob
eGambitUnsafe.AI_Score_74%
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Troj.Zbot.cz.(kcloud)
MicrosoftPWS:Win32/Zbot.gen!AF
ArcabitTrojan.Barys.DD4FB
GDataGen:Variant.Barys.54523
Acronissuspicious
McAfeePWS-Zbot.gen.bao
MAXmalware (ai score=99)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesMalware.Heuristic.1001
PandaTrj/CI.A
RisingTrojan.Generic@ML.92 (RDML:fDeh7M+V6dWXnO3V6DTBMg)
YandexTrojan.GenAsa!eEJ+0xDjhrA
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Kryptik.HZ!tr
AVGWin32:MalOb-ID [Cryp]
Paloaltogeneric.ml

How to remove Win32/Kryptik.AAUK?

Win32/Kryptik.AAUK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment