Malware

Win32/Kryptik.AUY removal tips

Malware Removal

The Win32/Kryptik.AUY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AUY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Creates a copy of itself

Related domains:

z.whorecord.xyz

How to determine Win32/Kryptik.AUY?


File Info:

crc32: 2E2CE80B
md5: 5fd88677ffc748cf9077ba2b4aa8400e
name: 5FD88677FFC748CF9077BA2B4AA8400E.mlw
sha1: 3b63b2263ed4489db9fc5f42024c6d35d3408f19
sha256: 76eb4d26046c455172212275f8e1923f0fd68bb60b9dde36913c0cb6dc2c5d65
sha512: 2d4edd7a1602960d65584f409fbb36416bfb13e567d6f19db0237336971cfaf3baf5d3e71a7bad0e0c0c19b6a6fd380916777892ae9cba6b45dd5da54dcebada
ssdeep: 24576:uIpTvppdtdudQs21Zb8oZ/finmHT1dTj6e:uIpTfL1Z4PmHTb
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Kryptik.AUY also known as:

K7AntiVirusTrojan ( 0057ffc71 )
LionicRiskware.Win32.BitCoinMiner.1!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MalwarebytesTrojan.Crypt.UPX
ZillyaTrojan.Kryptik.Win32.3483470
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaMalware:Win32/km_280b22.None
K7GWTrojan ( 005762bf1 )
Cybereasonmalicious.63ed44
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AUY
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
NANO-AntivirusRiskware.Win32.BitCoinMiner.ilwplr
TencentTrojan.Win32.Coinminer.yi
SophosMal/Generic-R + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34170.XmW@am73HHb
VIPREPacker.NSAnti.Gen (v)
TrendMicroTROJ_GEN.R002C0RIH21
McAfee-GW-EditionBehavesLike.Win32.Trickbot.bc
FireEyeGeneric.mg.5fd88677ffc748cf
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.BitCoinMiner.wkg
AviraTR/Crypt.ULPM.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.C689
MicrosoftTrojan:Win32/Azorult!ml
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
GDataWin32.Application.Coinminer.EZ4L4N
AhnLab-V3Malware/Gen.RL_Reputation.R365013
VBA32BScope.Trojan.Tiggre
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0RIH21
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EAHK!tr
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.AUY?

Win32/Kryptik.AUY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment