Malware

What is “Win32/Kryptik.AYGJ”?

Malware Removal

The Win32/Kryptik.AYGJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AYGJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.AYGJ?


File Info:

name: E688274C9F30FE8ED488.mlw
path: /opt/CAPEv2/storage/binaries/79bab86175b67a1575e8932df68b33f87d71b596bddfa67372e3c2019bf4027a
crc32: 01A4ACE4
md5: e688274c9f30fe8ed488f682a6e62e8b
sha1: 7df20d823f7b963e0d33b663da5c1d1cbe258436
sha256: 79bab86175b67a1575e8932df68b33f87d71b596bddfa67372e3c2019bf4027a
sha512: 71f938f08455d942c8ba46f020a29a8d8cbaac546c236df61738dc543d9bab8f735d721a7ea602c6f1e86434b15eef0de2067adfa56d948fe5025b37538598b4
ssdeep: 6144:D21crm+ZOg64KpxxbxDxxxx155nZxs1UoKZ8:a2mCOF4KxxbxDxxxx15VZx/8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A824ADAAA813FE7BC44E40F545AB47760E447FD3431BD083958DE98C96CE29A54B32B3
sha3_384: bf100671f98b8ae1912ee724347e98e01c9500b8ce4edc8b09584dfe9d79f331720e4e22e36e465425fc58eb3a71c56f
ep_bytes: 558bec515505413c000005413c000005
timestamp: 2013-04-08 15:28:36

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Win32/Kryptik.AYGJ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
SkyhighBehavesLike.Win32.PWSZbot.dh
ALYacTrojan.Ransom.Cerber.1
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.ShipUp.Win32.1324
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
K7GWTrojan ( 004cf6b81 )
Cybereasonmalicious.c9f30f
ArcabitTrojan.Ransom.Cerber.1
BaiduWin32.Trojan.Agent.eq
VirITI-WORM.Beagle.DM
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AYGJ
APEXMalicious
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
ClamAVWin.Packed.Shipup-6840804-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.ShipUp.brmngs
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Shipup.haw
EmsisoftTrojan.Ransom.Cerber.1 (B)
GoogleDetected
F-SecureTrojan.TR/Spy.Zbot.ppq
DrWebTrojan.Redirect.140
VIPRETrojan.Ransom.Cerber.1
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e688274c9f30fe8e
SophosTroj/Gyepis-A
IkarusTrojan.Win32.ShipUp
JiangminTrojan/ShipUp.jb
VaristW32/Zbot.JC.gen!Eldorado
AviraTR/Spy.Zbot.ppq
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
MicrosoftTrojan:Win32/ShipUp!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.15PGCIC
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGeneric-FAGO!E688274C9F30
MAXmalware (ai score=82)
VBA32Malware-Cryptor.Cidox.9413
Cylanceunsafe
PandaTrj/Hexas.HEU
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!J3LfvDkFx3I
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AXXI!tr
BitDefenderThetaGen:NN.ZexaF.36802.oG1@aOnGa7jc
AVGWin32:Gepys-E [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Shipup.503f0578

How to remove Win32/Kryptik.AYGJ?

Win32/Kryptik.AYGJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment