Home Malware Programs Trojans Trojan.Crypt

Trojan.Crypt

Posted: November 11, 2009

Threat Metric

Ranking: 9,257
Threat Level: 9/10
Infected PCs: 11,940
First Seen: July 24, 2009
Last Seen: October 5, 2023
OS(es) Affected: Windows

Trojan.Crypt is a browser hijacker that implements changes in your Web-browsing settings that allow Trojan.Crypt to redirect you to unsafe or unwanted websites. Although Trojan.Crypt most recently was identified in a fraudulent marketing effort for Twitch channel 'bombing' campaigns, associated evidence also implies that Trojan.Crypt may be in distribution on networks for pirated game software. Like any Trojan, Trojan.Crypt is a threat that actively tries to harm your PC's security; removing Trojan.Crypt ordinarily should use appropriate, up-to-date and reputable anti-malware tools.

A New Browser Problem for Would-Be Shepherds of Gamers

Trojan.Crypt previously made its home at the (now terminated) Web domain of twitchbomber.pw, and was disguised to resemble a Twitch channel-redirecting bot, available for rental by suitably unscrupulous individuals. Rather than being an actual bot, Trojan.Crypt is a threatening software that duplicates the primary purpose of many toolbars: taking over your homepage. Modifications made by Trojan.Crypt allow Trojan.Crypt to reset any individual Web browser's homepage to an arbitrary URL, potentially including websites that include other attacks against the infected PC. However, malware researchers also found other attacks linked to Trojan.Crypt's feature set that may include:

  • Trojan.Crypt gathers basic system information and uploads this stolen data to a remote server. Information like Your Windows Product ID may be used in future attacks to compromise your system.
  • Trojan.Crypt also includes a function meant to disable popular memory-management utilities, such as Task Manager or Process Explorer. Such attacks may prevent you from terminating memory processes that link to threats like Trojan.Crypt.

Trojan.Crypt's distribution at twitchbomber.pw shows some of the dangers in attempting to hire illegal software to conduct browser-based attacks. Although actual threat kits available for third-party use comprise of a significant part of the threats black market, Trojan.Crypt is designed to infect its 'clients' without providing the so-called Twitch bombing features its website claims Trojan.Crypt possesses.

Keeping Your Gaming Machine out of a Crypt

Previously-gathered file information for Trojan.Crypt implies that Trojan.Crypt may be in distribution as a fake installer for the DayZ zombie survival game, or as a media management utility. Regardless of the path Trojan.Crypt may have taken to reach your PC, Trojan.Crypt is a threatening software whose extermination is critical for your PC's privacy and security. Fortunately, many brands of anti-malware products are confirmed to be able to identify and remove Trojan.Crypt, which should be deletable after a standard system scan. Some products also may identify Trojan.Crypt's last known website as unsafe, although visiting it still may not be safe.

The need for Web traffic is one of the top drivers of both threatening and legitimate software development, and, in some cases, the dissimilarity between them may not be easy to discern. However, if you've contemplated using third-party bots and other utilities to violate the terms of a popular site's services, malware experts might suggest that the existence of a misleading tactic like Trojan.Crypt provides ample reasons to avoid doing so.

Aliases

W32/FakeAV.AT!tr [Fortinet]Trojan.SuspectCRC [Ikarus]Mal/FakeAV-RM [Sophos]Artemis!83813E9B34E6 [McAfee-GW-Edition]Trojan.Siggen4.4537 [DrWeb]Trojan.Win32.Diple.fjou [Kaspersky]Win32:Kryptik-IWZ [Trj] [Avast]a variant of Win32/Kryptik.AGTO [NOD32]Generic_r.CFW [AVG]W32/Ruskill.SET!tr.bdr [Fortinet]BackDoor.IRC.NgrBot.42 [DrWeb]Backdoor.Win32.Ruskill.set [Kaspersky]Artemis!BC2503958592 [McAfee]W32/Internet-Trojan-patched-based!Maximus [F-Prot]Artemis!A6C1BA7D6FF7 [McAfee]
More aliases (1506)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\ICC\ICC.exe File name: ICC.exe
Size: 7.4 MB (7401472 bytes)
MD5: 6db21ac72230cc165dc7f3f070f183e8
Detection count: 248
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\ICC\ICC.exe
Group: Malware file
Last Updated: September 19, 2023
G:\OS\HDDlife Pro 4.0.192\~Get Your Software Here\Crack\HDDlifePro.exe File name: HDDlifePro.exe
Size: 4.11 MB (4115456 bytes)
MD5: d12b0124a5b14215bc50dd181600b1c8
Detection count: 199
File type: Executable File
Mime Type: unknown/exe
Path: G:\OS\HDDlife Pro 4.0.192\~Get Your Software Here\Crack\HDDlifePro.exe
Group: Malware file
Last Updated: October 13, 2023
%WINDIR%\tracing\svchost.exe File name: svchost.exe
Size: 38.56 MB (38567936 bytes)
MD5: ca05405c75d9f091c0f96dc2dcac79fa
Detection count: 164
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\tracing
Group: Malware file
Last Updated: April 4, 2021
%PROGRAMFILES(x86)%\Minitab\Minitab 16\Auth\haspdinst.exe File name: haspdinst.exe
Size: 48.12 KB (48128 bytes)
MD5: 034fb2034aa371696bd89f1c367d3e88
Detection count: 138
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Minitab\Minitab 16\Auth\haspdinst.exe
Group: Malware file
Last Updated: May 24, 2023
%SystemDrive%\Documents and Settings\Mr.Nelson\Application Data\A.exe File name: A.exe
Size: 1.57 MB (1579520 bytes)
MD5: c2ef64096f90550b90a0bff1ae4a231a
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\Mr.Nelson\Application Data
Group: Malware file
Last Updated: January 14, 2013
C:\INSTALVERS\WINDOWS_7_64\SOFT\diag\Powerstrip386650fullinclcracked\PStrip.exe File name: PStrip.exe
Size: 936.82 KB (936824 bytes)
MD5: b2ca61f8248d221a5b2f0576edb7292c
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: C:\INSTALVERS\WINDOWS_7_64\SOFT\diag\Powerstrip386650fullinclcracked\PStrip.exe
Group: Malware file
Last Updated: March 4, 2023
%PROGRAMFILES(x86)%\ElcomSoft\Distributed Password Recovery\esdprs.exe File name: esdprs.exe
Size: 333.58 KB (333584 bytes)
MD5: a6c1ba7d6ff7a014661af50a3c6907b1
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\ElcomSoft\Distributed Password Recovery
Group: Malware file
Last Updated: February 16, 2021
%LOCALAPPDATA%\ATI\Apps\vufcudu.dll File name: vufcudu.dll
Size: 334.84 KB (334848 bytes)
MD5: 1ab7ed19799a5d61a00de366b97c645c
Detection count: 37
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\ATI\Apps
Group: Malware file
Last Updated: November 26, 2012
%SystemDrive%\RECYCLER\S-1-5-21-448539723-507921405-839522115-1004\$6408c339ffec0d9582449de47815c1f3\n. File name: n.
Size: 77.31 KB (77312 bytes)
MD5: 6d543fdcba2c189cb7cf2bc1f516d6c2
Detection count: 35
Path: %SystemDrive%\RECYCLER\S-1-5-21-448539723-507921405-839522115-1004\$6408c339ffec0d9582449de47815c1f3
Group: Malware file
Last Updated: October 12, 2012
%APPDATA%\cpjksvxxyviutjyixjx.exe File name: cpjksvxxyviutjyixjx.exe
Size: 1.16 MB (1162568 bytes)
MD5: 901953524328da3f3fe7d123473cb275
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: March 21, 2013
%ALLUSERSPROFILE%\Sext.exe File name: Sext.exe
Size: 950.27 KB (950272 bytes)
MD5: b64b36533cbf3b136f0c554f1152f883
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: December 24, 2012
%WINDIR%\system32\DLL321.dll File name: DLL321.dll
Size: 299.4 KB (299400 bytes)
MD5: 5e2478823c3185f5139aa0c02076422d
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: October 22, 2012
%SystemDrive%\RECYCLER\S-1-5-21-299502267-507921405-725345543-500\$6da742a366a21a6962f6d185cb0c0216\n. File name: n.
Size: 77.31 KB (77312 bytes)
MD5: 279a7ada1130ac15e1b5d351c1f3413f
Detection count: 9
Path: %SystemDrive%\RECYCLER\S-1-5-21-299502267-507921405-725345543-500\$6da742a366a21a6962f6d185cb0c0216
Group: Malware file
Last Updated: November 13, 2012
%WINDIR%\system32\mlserver.exe File name: mlserver.exe
Size: 42.49 KB (42496 bytes)
MD5: 8a3e36a7b99adb9fc5a465b089a2c502
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: May 13, 2013
%USERPROFILE%\48b83f83_1639.exe File name: 48b83f83_1639.exe
Size: 72.7 KB (72704 bytes)
MD5: 164b60a61af008af6960a2d226925af2
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: October 22, 2012
%SystemDrive%\RECYCLER\S-1-5-21-2052111302-1647877149-682003330-1003\$efe6035451674d1641b60a35e3fabc4d\n. File name: n.
Size: 77.31 KB (77312 bytes)
MD5: cad6964e293a6cb88003cfcb8a1dd843
Detection count: 5
Path: %SystemDrive%\RECYCLER\S-1-5-21-2052111302-1647877149-682003330-1003\$efe6035451674d1641b60a35e3fabc4d
Group: Malware file
Last Updated: October 12, 2012
%WINDIR%\system32\RVHOST.exe File name: RVHOST.exe
Size: 403.45 KB (403456 bytes)
MD5: 43a5008095b5b5e435991d5f3e798173
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: October 24, 2012
%USERPROFILE%\3yyp.exe File name: 3yyp.exe
Size: 200.24 KB (200241 bytes)
MD5: 770a85f087551d3962bf802492570d9b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: October 29, 2012
%TEMP%\Traymonitor.exe File name: Traymonitor.exe
Size: 911.87 KB (911872 bytes)
MD5: 6242ca7bddd32a150421b2aefbf6a81e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: March 29, 2013
%COMMONPROGRAMFILES%\Microsoft Shared\MSINFO\Backup.exe File name: Backup.exe
Size: 1.84 MB (1846272 bytes)
MD5: 75728dba25981a1556578682b109f696
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\Microsoft Shared\MSINFO
Group: Malware file
Last Updated: April 29, 2013

More files

Related Posts

Loading...