Home Malware Programs Trojans Trojan.Kryptik

Trojan.Kryptik

Posted: October 5, 2009

Threat Metric

Ranking: 1,652
Threat Level: 9/10
Infected PCs: 422,187
First Seen: July 24, 2009
Last Seen: March 23, 2024
OS(es) Affected: Windows

Trojan.Kryptik is a dangerous computer Trojan horse. Once a system is infected with Trojan.Kryptik it can then recreate itself making it very difficult to manually detect and remove. Trojan.Kryptik is able to load at startup where it could compromise the infected system allowing an outside attacker to gain access.

Aliases

MSIL6.EHL [AVG]MSIL/Kryptik.AQZ!tr [Fortinet]Trojan.MSIL.Crypt [Ikarus]Trojan/Win32.Agent [AhnLab-V3]TrojanClicker:MSIL/Ezbro.C [Microsoft]Trojan/MSIL.Kryptik [Antiy-AVL]RDN/Generic.dx!dh3 [McAfee-GW-Edition]Troj/MSIL-BIN [Sophos]Trojan.MSIL.Kryptik.bnm [Kaspersky]Win32:Kryptik-OUJ [Trj] [Avast]Trojan.Gen.2 [Symantec]Trojan ( 004b21881 ) [K7AntiVirus]TrojanClicker.Ezbro.r3 [CAT-QuickHeal]Mal/Cleaman-B [Sophos]Trojan.DownLoader6.20538 [DrWeb]
More aliases (1020)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\4207961.exe File name: 4207961.exe
Size: 47.61 KB (47616 bytes)
MD5: 1d095bc417db73c6bc6e4c4e7b43106f
Detection count: 97,537
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\4207961.exe
Group: Malware file
Last Updated: December 24, 2023
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 82.72 KB (82723 bytes)
MD5: 643c2766067a08abd9d6a67b838f9e8d
Detection count: 1,771
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: June 13, 2023
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 62.05 KB (62050 bytes)
MD5: 8f3cd34fe7c83e93028c884c31f43ea1
Detection count: 1,251
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: June 16, 2020
C:\Users\<username>\AppData\Local\Temp\Low\SessionWin32k\1750\conhost.exe File name: conhost.exe
Size: 274.94 KB (274944 bytes)
MD5: 39ac4626bb55759fc9c376e7b33dc0a1
Detection count: 1,033
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Low\SessionWin32k\1750\conhost.exe
Group: Malware file
Last Updated: July 9, 2022
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 79.56 KB (79564 bytes)
MD5: f8b2526ac4dedfd4733557fc97f337c5
Detection count: 871
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: December 21, 2023
%WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin\update.vbe File name: update.vbe
Size: 60.59 KB (60597 bytes)
MD5: 23f854fbe137948c16a3bf54daf3eaf4
Detection count: 351
Mime Type: unknown/vbe
Path: %WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin
Group: Malware file
Last Updated: August 14, 2021
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\olm.exe File name: olm.exe
Size: 358.4 KB (358400 bytes)
MD5: 02306dc6be32bcdc6d3ff742058d2ead
Detection count: 351
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\olm.exe
Group: Malware file
Last Updated: June 27, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Chromium Updating.exe File name: Chromium Updating.exe
Size: 711.16 KB (711168 bytes)
MD5: cdf251106ab7dea1ae4ce307f4e352ff
Detection count: 311
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Chromium Updating.exe
Group: Malware file
Last Updated: August 6, 2020
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 61.36 KB (61360 bytes)
MD5: db13fce9c4130069467fa241d9d5fbfb
Detection count: 199
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: May 7, 2016
%APPDATA%\update.vbe File name: update.vbe
Size: 6.63 KB (6639 bytes)
MD5: e9d8cc92a20976d2a65d43679e001df3
Detection count: 138
Mime Type: unknown/vbe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2016
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 60.11 KB (60113 bytes)
MD5: 414069362d4543b2e6cdcb2c42e579de
Detection count: 115
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: September 2, 2020
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 114.79 KB (114797 bytes)
MD5: df1b86eaab233b4db38af491d7f825ff
Detection count: 108
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: May 7, 2016
%APPDATA%\update.vbe File name: update.vbe
Size: 8.47 KB (8477 bytes)
MD5: 6ea451ebad14d129335c5b39d8be02c3
Detection count: 91
Mime Type: unknown/vbe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2016
%WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin\update.vbe File name: update.vbe
Size: 123.56 KB (123562 bytes)
MD5: 42c573073d35a0005b6ee175800f9506
Detection count: 82
Mime Type: unknown/vbe
Path: %WINDIR%\system32\config\systemprofile\AppData\Roaming\Origin
Group: Malware file
Last Updated: May 7, 2016
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\nvc.exe File name: nvc.exe
Size: 752.64 KB (752640 bytes)
MD5: a1bcc11cc6e4e76108b212efc8643770
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\nvc.exe
Group: Malware file
Last Updated: June 26, 2020
%SystemDrive%\48a5ab98\48a5ab98.exe File name: 48a5ab98.exe
Size: 253.95 KB (253952 bytes)
MD5: 1c9493b8aaffd624c97c37834200d610
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\48a5ab98
Group: Malware file
Last Updated: April 3, 2015
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 79.36 KB (79360 bytes)
MD5: 5e06e0e3b0cd13f86ad2dc9b274282d9
Detection count: 56
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: August 30, 2020
%APPDATA%\update.vbe File name: update.vbe
Size: 2.62 KB (2624 bytes)
MD5: fb5ff65ef266d3bce00529268a058e9c
Detection count: 42
Mime Type: unknown/vbe
Path: %APPDATA%
Group: Malware file
Last Updated: May 7, 2016
c:\Users\<username>\appdata\local\tallidle\aoqinvirtual\michll_seder.dll File name: michll_seder.dll
Size: 268.8 KB (268800 bytes)
MD5: 7e2f97d9d78ce67e3e41fccc51a6e4d4
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\Users\<username>\appdata\local\tallidle\aoqinvirtual\michll_seder.dll
Group: Malware file
Last Updated: February 8, 2022
%ALLUSERSPROFILE%\RuqoHugxa\IejcEnye.xnr File name: IejcEnye.xnr
Size: 301.05 KB (301056 bytes)
MD5: 5fadc590216e4a92143b598b6aed210b
Detection count: 13
Mime Type: unknown/xnr
Path: %ALLUSERSPROFILE%\RuqoHugxa
Group: Malware file
Last Updated: December 30, 2014
4131500ab1d4e9f620e5101e51d98587 File name: 4131500ab1d4e9f620e5101e51d98587
Size: 453.95 KB (453956 bytes)
MD5: 4131500ab1d4e9f620e5101e51d98587
Detection count: 12
Group: Malware file
14.exe File name: 14.exe
Size: 135.16 KB (135168 bytes)
MD5: 417494bee98a01655f9f13d4d5efb12f
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathscaalqtw.exeRegexp file mask%ALLUSERSPROFILE%\sqldump.exe%APPDATA%\b[NUMBERS].exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\[RANDOM CHARACTERS].com.url%APPDATA%\Origin\update.vbe%APPDATA%\Stanfind.exe%APPDATA%\vpn gui.exe%LOCALAPPDATA%\Microsoft\Windows\Symbols\wvfilters.sys%TEMP%\nvc.exe%TEMP%\system.exe%TEMP%\winsrvcs32.exe

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\windrivgr 19.7%LOCALAPPDATA%\DsHcaJnIIz

Related Posts

One Comment

Loading...