Trojan.Kryptik
Posted: October 5, 2009
Threat Metric
The Threat Meter is a malware assessment that SpywareRemove.com's research team is able to
give every identifiable malware threat. Our Threat Meter includes several criteria based off of
specific malware threats to value their severity, reach and volume. The Threat Meter is able to give
you a numerical breakdown of each threat's initial Threat Level, Detection Count, Volume Count,
Trend Path and Percentage Impact. The overall ranking of each threat in the Threat Meter is a basic
breakdown of how all threats are ranked within our own extensive malware database. The scoring for
each specific malware threat can be easily compared to other emerging threats to draw a contrast in
its particular severity. The Threat Meter is a useful tool in the endeavor of seeking a solution to
remove a threat or pursue additional analytical research for all types of computer users.
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 1,652 |
---|---|
Threat Level: | 9/10 |
Infected PCs: | 422,187 |
First Seen: | July 24, 2009 |
---|---|
Last Seen: | March 23, 2024 |
OS(es) Affected: | Windows |
Trojan.Kryptik is a dangerous computer Trojan horse. Once a system is infected with Trojan.Kryptik it can then recreate itself making it very difficult to manually detect and remove. Trojan.Kryptik is able to load at startup where it could compromise the infected system allowing an outside attacker to gain access.
Aliases
MSIL6.EHL [AVG]MSIL/Kryptik.AQZ!tr [Fortinet]Trojan.MSIL.Crypt [Ikarus]Trojan/Win32.Agent [AhnLab-V3]TrojanClicker:MSIL/Ezbro.C [Microsoft]Trojan/MSIL.Kryptik [Antiy-AVL]RDN/Generic.dx!dh3 [McAfee-GW-Edition]Troj/MSIL-BIN [Sophos]Trojan.MSIL.Kryptik.bnm [Kaspersky]Win32:Kryptik-OUJ [Trj] [Avast]Trojan.Gen.2 [Symantec]Trojan ( 004b21881 ) [K7AntiVirus]TrojanClicker.Ezbro.r3 [CAT-QuickHeal]Mal/Cleaman-B [Sophos]Trojan.DownLoader6.20538 [DrWeb]
More aliases (1020)
More aliases (1020)
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:C:\Users\<username>\AppData\Roaming\4207961.exe
File name: 4207961.exeSize: 47.61 KB (47616 bytes)
MD5: 1d095bc417db73c6bc6e4c4e7b43106f
Detection count: 97,537
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\4207961.exe
Group: Malware file
Last Updated: December 24, 2023
%APPDATA%\Origin\update.vbe
File name: update.vbeSize: 82.72 KB (82723 bytes)
MD5: 643c2766067a08abd9d6a67b838f9e8d
Detection count: 1,771
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: June 13, 2023
%APPDATA%\Origin\update.vbe
File name: update.vbeSize: 62.05 KB (62050 bytes)
MD5: 8f3cd34fe7c83e93028c884c31f43ea1
Detection count: 1,251
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: June 16, 2020
C:\Users\<username>\AppData\Local\Temp\Low\SessionWin32k\1750\conhost.exe
File name: conhost.exeSize: 274.94 KB (274944 bytes)
MD5: 39ac4626bb55759fc9c376e7b33dc0a1
Detection count: 1,033
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Low\SessionWin32k\1750\conhost.exe
Group: Malware file
Last Updated: July 9, 2022
%APPDATA%\Origin\update.vbe
File name: update.vbeSize: 79.56 KB (79564 bytes)
MD5: f8b2526ac4dedfd4733557fc97f337c5
Detection count: 871
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: December 21, 2023
%WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin\update.vbe
File name: update.vbeSize: 60.59 KB (60597 bytes)
MD5: 23f854fbe137948c16a3bf54daf3eaf4
Detection count: 351
Mime Type: unknown/vbe
Path: %WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin
Group: Malware file
Last Updated: August 14, 2021
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\olm.exe
File name: olm.exeSize: 358.4 KB (358400 bytes)
MD5: 02306dc6be32bcdc6d3ff742058d2ead
Detection count: 351
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\olm.exe
Group: Malware file
Last Updated: June 27, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Chromium Updating.exe
File name: Chromium Updating.exeSize: 711.16 KB (711168 bytes)
MD5: cdf251106ab7dea1ae4ce307f4e352ff
Detection count: 311
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Chromium Updating.exe
Group: Malware file
Last Updated: August 6, 2020
%APPDATA%\Origin\update.vbe
File name: update.vbeSize: 61.36 KB (61360 bytes)
MD5: db13fce9c4130069467fa241d9d5fbfb
Detection count: 199
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: May 7, 2016
%APPDATA%\update.vbe
File name: update.vbeSize: 6.63 KB (6639 bytes)
MD5: e9d8cc92a20976d2a65d43679e001df3
Detection count: 138
Mime Type: unknown/vbe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2016
%APPDATA%\Origin\update.vbe
File name: update.vbeSize: 60.11 KB (60113 bytes)
MD5: 414069362d4543b2e6cdcb2c42e579de
Detection count: 115
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: September 2, 2020
%APPDATA%\Origin\update.vbe
File name: update.vbeSize: 114.79 KB (114797 bytes)
MD5: df1b86eaab233b4db38af491d7f825ff
Detection count: 108
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: May 7, 2016
%APPDATA%\update.vbe
File name: update.vbeSize: 8.47 KB (8477 bytes)
MD5: 6ea451ebad14d129335c5b39d8be02c3
Detection count: 91
Mime Type: unknown/vbe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2016
%WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin\update.vbe
File name: update.vbeSize: 123.56 KB (123562 bytes)
MD5: 42c573073d35a0005b6ee175800f9506
Detection count: 82
Mime Type: unknown/vbe
Path: %WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin
Group: Malware file
Last Updated: May 7, 2016
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\nvc.exe
File name: nvc.exeSize: 752.64 KB (752640 bytes)
MD5: a1bcc11cc6e4e76108b212efc8643770
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\nvc.exe
Group: Malware file
Last Updated: June 26, 2020
%SystemDrive%\48a5ab98\48a5ab98.exe
File name: 48a5ab98.exeSize: 253.95 KB (253952 bytes)
MD5: 1c9493b8aaffd624c97c37834200d610
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\48a5ab98
Group: Malware file
Last Updated: April 3, 2015
%APPDATA%\Origin\update.vbe
File name: update.vbeSize: 79.36 KB (79360 bytes)
MD5: 5e06e0e3b0cd13f86ad2dc9b274282d9
Detection count: 56
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: August 30, 2020
%APPDATA%\update.vbe
File name: update.vbeSize: 2.62 KB (2624 bytes)
MD5: fb5ff65ef266d3bce00529268a058e9c
Detection count: 42
Mime Type: unknown/vbe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2016
c:\Users\<username>\appdata\local\tallidle\aoqinvirtual\michll_seder.dll
File name: michll_seder.dllSize: 268.8 KB (268800 bytes)
MD5: 7e2f97d9d78ce67e3e41fccc51a6e4d4
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\Users\<username>\appdata\local\tallidle\aoqinvirtual\michll_seder.dll
Group: Malware file
Last Updated: February 8, 2022
%ALLUSERSPROFILE%\RuqoHugxa\IejcEnye.xnr
File name: IejcEnye.xnrSize: 301.05 KB (301056 bytes)
MD5: 5fadc590216e4a92143b598b6aed210b
Detection count: 13
Mime Type: unknown/xnr
Path: %ALLUSERSPROFILE%\RuqoHugxa
Group: Malware file
Last Updated: December 30, 2014
4131500ab1d4e9f620e5101e51d98587
File name: 4131500ab1d4e9f620e5101e51d98587Size: 453.95 KB (453956 bytes)
MD5: 4131500ab1d4e9f620e5101e51d98587
Detection count: 12
Group: Malware file
14.exe
File name: 14.exeSize: 135.16 KB (135168 bytes)
MD5: 417494bee98a01655f9f13d4d5efb12f
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
More files
Registry Modifications
The following newly produced Registry Values are:
File name without pathscaalqtw.exeRegexp file mask%ALLUSERSPROFILE%\sqldump.exe%APPDATA%\b[NUMBERS].exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\[RANDOM CHARACTERS].com.url%APPDATA%\Origin\update.vbe%APPDATA%\Stanfind.exe%APPDATA%\vpn gui.exe%LOCALAPPDATA%\Microsoft\Windows\Symbols\wvfilters.sys%TEMP%\nvc.exe%TEMP%\system.exe%TEMP%\winsrvcs32.exe
File name without pathscaalqtw.exeRegexp file mask%ALLUSERSPROFILE%\sqldump.exe%APPDATA%\b[NUMBERS].exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\[RANDOM CHARACTERS].com.url%APPDATA%\Origin\update.vbe%APPDATA%\Stanfind.exe%APPDATA%\vpn gui.exe%LOCALAPPDATA%\Microsoft\Windows\Symbols\wvfilters.sys%TEMP%\nvc.exe%TEMP%\system.exe%TEMP%\winsrvcs32.exe
Additional Information
The following directories were created:
%ALLUSERSPROFILE%\windrivgr 19.7%LOCALAPPDATA%\DsHcaJnIIz
Thank you very much i eliminate virus from my computer thanks