Malware

Win32/Kryptik.NQY removal guide

Malware Removal

The Win32/Kryptik.NQY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.NQY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.NQY?


File Info:

name: 72D29A8ED0A510F5733C.mlw
path: /opt/CAPEv2/storage/binaries/d6212726cd738d333a93b7eaa6b6f70ae75dd882e1480605c241f40feb0d0b18
crc32: ECDA1B52
md5: 72d29a8ed0a510f5733c427aeea4dae2
sha1: 4bd32f67f287f23a4fe71143a019462ed5077163
sha256: d6212726cd738d333a93b7eaa6b6f70ae75dd882e1480605c241f40feb0d0b18
sha512: de0cc0db6b338284c762385c33e528d9e33799a1097c27276e3e64cb30131a2cd0c94bc08c2e8b8fce3f106f5b21a8a240508fedc56ac9dcbdf90319b255bcbf
ssdeep: 12288:PDZi898g5GamzOmP1jwPCWzW6PB3XGM4SnzZIoS:di8iwBmzOY1Yw6PxGYt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F2B42350B5A53361F3AF00B13D15287D216EA9B5DEC05CECBDDCB06EF245BB8B9A0648
sha3_384: b6892d99a541b642a906f62225a2746ac2468c5286cf996c0e8c3f2ce2fa5b3a22f66dc388dda52f6b228b4632c750bf
ep_bytes: 60be00e044008dbe0030fbffc7871810
timestamp: 1970-02-17 02:23:58

Version Info:

CompanyName: BitDefender S.R.L.
FileDescription: BitDefender Antivirus Scanner
FileVersion: 13,0,21,1
InternalName: UIScanner
LegalCopyright: Copyright (C) 2010
OriginalFilename: uiscan.exe
ProductName: BitDefender 2010
ProductVersion: 13,0,18,344
Translation: 0x0409 0x04b0

Win32/Kryptik.NQY also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
DrWebTrojan.Fakealert.21226
MicroWorld-eScanGen:Heur.FKP.!c!.1
McAfeeFakeAV-SecurityTool.jq
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.FakeAV.Win32.75683
K7AntiVirusTrojan ( 00285f321 )
K7GWTrojan ( 00285f321 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.36250.EmKfauSNb2dQ
VirITTrojan.Win32.Crypter.O
CyrenW32/FakeAlert.SU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.NQY
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.FKP.!c!.1
NANO-AntivirusTrojan.Win32.Crypted.dboee
SUPERAntiSpywareTrojan.Agent/Gen-FraudLoad
AvastWin32:MalOb-GG [Cryp]
RisingTrojan.Necurs!8.B03 (TFE:5:XQxpsSI7UxF)
EmsisoftGen:Heur.FKP.!c!.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Heur.FKP.!c!.1
McAfee-GW-EditionFakeAV-SecurityTool.jq
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.72d29a8ed0a510f5
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.FKP.!c!.1
JiangminTrojan.Generic.ekrvm
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.FKP.!c!.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Bulta!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R5355
VBA32BScope.Trojan.FakeAlert
ALYacGen:Heur.FKP.!c!.1
Cylanceunsafe
PandaGeneric Suspicious
TencentMalware.Win32.Gencirc.10be804a
YandexTrojan.GenAsa!8otwvUoYQIY
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Yakes.dwnc
FortinetW32/BrowHost.KP!tr
AVGWin32:MalOb-GG [Cryp]
Cybereasonmalicious.ed0a51
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.NQY?

Win32/Kryptik.NQY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment