Malware

Win32/Kryptik.AYGJ removal tips

Malware Removal

The Win32/Kryptik.AYGJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AYGJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.AYGJ?


File Info:

name: 830458A34A4B2397F965.mlw
path: /opt/CAPEv2/storage/binaries/62a671d301097d5f791c9a84022a5fefc9cbe903d314311908af74698be603c8
crc32: D35C5C0B
md5: 830458a34a4b2397f96529481568ca99
sha1: a623b1508ea68fe3976c2668fd1593d832448231
sha256: 62a671d301097d5f791c9a84022a5fefc9cbe903d314311908af74698be603c8
sha512: 88ad5f423d9a82caf06deea7ec9b5fda829c9dec02daa02e1db4bed1c8a8fe881789925518237eb58a65481047f77b4214b349b2a9fbcc98aea0ae74c5c94601
ssdeep: 3072:Rc/1zMIQ+UuTF0TNgXO5WjjhP/9bH+q6f15TGzhK1/zmKakJ:eMf+UukiOWdFHoLTGzIFmK1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19734D002705D0823DC2A6B76450E09FB85BCADAC5FD4226EA6D3F8DCF571772672B052
sha3_384: cc16fed3278a650bf05d98c72816c42a4704c37df4c22763e4128bdaa0d1b7ea342e0b19bbbe107903e0eee550100058
ep_bytes: 558bec515505413c000005413c000005
timestamp: 2013-04-07 18:45:33

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Win32/Kryptik.AYGJ also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Redirect.140
MicroWorld-eScanTrojan.Ransom.Cerber.1
ClamAVWin.Trojan.Redirect-6055402-0
FireEyeGeneric.mg.830458a34a4b2397
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.Cerber.1
Cylanceunsafe
ZillyaTrojan.Generic.Win32.686106
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004cf6b81 )
K7GWTrojan ( 004cf6b81 )
Cybereasonmalicious.08ea68
BitDefenderThetaGen:NN.ZexaF.36722.oi1@auAx3Ylc
CyrenW32/Agent.BKB.gen!Eldorado
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AYGJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Redirect.brmyoq
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Kryptik.16000652
EmsisoftTrojan.Ransom.Cerber.1 (B)
F-SecureTrojan.TR/Spy.Zbot.ppq
BaiduWin32.Trojan.Agent.eq
VIPRETrojan.Ransom.Cerber.1
TrendMicroTROJ_KRYPTK.SMAD
McAfee-GW-EditionPWS-Zbot-FATG!830458A34A4B
Trapminemalicious.high.ml.score
SophosTroj/Gyepis-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.15PGCIC
JiangminTrojan/ShipUp.jb
WebrootW32.Malware.Gen
AviraTR/Spy.Zbot.ppq
MAXmalware (ai score=87)
Antiy-AVLTrojan[Dropper]/Win32.Gepys
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
ArcabitTrojan.Ransom.Cerber.1
ViRobotTrojan.Win32.Gepys.216608
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Kryptk.C3122826
Acronissuspicious
VBA32Malware-Cryptor.Cidox.9413
MalwarebytesTrojan.Dropper
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!J3LfvDkFx3I
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AXXI!tr
AVGWin32:Gepys-E [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.AYGJ?

Win32/Kryptik.AYGJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment