Malware

How to remove “Win32/Kryptik.AYCK”?

Malware Removal

The Win32/Kryptik.AYCK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AYCK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.AYCK?


File Info:

name: E5992E9E0871DEF618A8.mlw
path: /opt/CAPEv2/storage/binaries/37cb0ed4fc724fd7f93dc103a4f4058e707946257a27bae6a6a9166168da62bb
crc32: 691A86AD
md5: e5992e9e0871def618a83a1f5f91b765
sha1: b89d26f96d4174903219d9f8058be7f2d0a10161
sha256: 37cb0ed4fc724fd7f93dc103a4f4058e707946257a27bae6a6a9166168da62bb
sha512: c31b005f85915d6c794f137452996cb6a571371c5a746a6037bb049a049f371e63a39f082fe22dbc7b51c13fb72350090e157853aa574670baf68b79e4386269
ssdeep: 3072:AJak9Lqut//aVLTG098c9vvKK+PUrHiOb3BS2PxW8sR15u3Vr:AJtLq8aVN984UP8CO7gexWDVu5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAF31342C36D8183D5DDA6B7083922B2B7BD510A2541BF8D6FA366EE783A7C74385D20
sha3_384: 27e7b649d9e7ec598d798fc7d99715a1bb77c98050f1e4854a2d9dcf38dc1db2dcda0623c3dd91d131c2a6fdd5499f8f
ep_bytes: 60be007043008dbe00a0fcff5783cdff
timestamp: 2013-04-05 05:06:43

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Win32/Kryptik.AYCK also known as:

BkavW32.AIDetectMalware
AVGWin32:Zbot-UQA [Trj]
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKDZ.94716
FireEyeGeneric.mg.e5992e9e0871def6
SkyhighBehavesLike.Win32.PWSZbot.cc
McAfeePWS-Zbot-FATG!F2D0B8F4862E
MalwarebytesTrojan.Dropper
ZillyaTrojan.ShipUp.Win32.1304
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.jmLfaWCxIKgc
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYCK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Shipup-6840300-0
KasperskyVHO:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKDZ.94716
AvastWin32:Zbot-UQA [Trj]
TencentTrojan.Win32.Kryptik.16000652
EmsisoftTrojan.GenericKDZ.94716 (B)
BaiduWin32.Trojan.Agent.eq
F-SecureTrojan.TR/Obfuscate.adj
DrWebTrojan.Redirect.140
VIPRETrojan.GenericKDZ.94716
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.moderate.ml.score
SophosTroj/Gyepis-A
IkarusTrojan.Win32.ShipUp
GDataWin32.Trojan.PSE.1A06N6
JiangminTrojan/Generic.avokq
VaristW32/Kryptik.JSF.gen!Eldorado
AviraTR/Obfuscate.adj
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.b.973
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Generic.D171FC
ZoneAlarmVHO:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Zbot!pz
GoogleDetected
AhnLab-V3Trojan/RL.Kryptk.R256160
Acronissuspicious
VBA32BScope.Trojan.Redirect
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!8.8 (TFE:5:tCVlQCkw0F)
YandexTrojan.GenAsa!Pg/3K5KKc74
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AXXI!tr
Cybereasonmalicious.e0871d
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.AYCK?

Win32/Kryptik.AYCK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment