Home Malware Programs Trojans Trojan.Kryptik

Trojan.Kryptik

Posted: October 5, 2009

Threat Metric

Ranking: 643
Threat Level: 9/10
Infected PCs: 448,533
First Seen: July 24, 2009
Last Seen: March 10, 2025
OS(es) Affected: Windows

Trojan.Kryptik is a dangerous computer Trojan horse. Once a system is infected with Trojan.Kryptik it can then recreate itself making it very difficult to manually detect and remove. Trojan.Kryptik is able to load at startup where it could compromise the infected system allowing an outside attacker to gain access.

Aliases

MSIL6.EHL [AVG]MSIL/Kryptik.AQZ!tr [Fortinet]Trojan.MSIL.Crypt [Ikarus]Trojan/Win32.Agent [AhnLab-V3]TrojanClicker:MSIL/Ezbro.C [Microsoft]Trojan/MSIL.Kryptik [Antiy-AVL]RDN/Generic.dx!dh3 [McAfee-GW-Edition]Troj/MSIL-BIN [Sophos]Trojan.MSIL.Kryptik.bnm [Kaspersky]Win32:Kryptik-OUJ [Trj] [Avast]Trojan.Gen.2 [Symantec]Trojan ( 004b21881 ) [K7AntiVirus]TrojanClicker.Ezbro.r3 [CAT-QuickHeal]Mal/Cleaman-B [Sophos]Trojan.DownLoader6.20538 [DrWeb]
More aliases (1020)

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Trojan.Kryptik may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\4207961.exe File name: 4207961.exe
Size: 47.61 KB (47616 bytes)
MD5: 1d095bc417db73c6bc6e4c4e7b43106f
Detection count: 97,570
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\4207961.exe
Group: Malware file
Last Updated: November 5, 2024
C:\Users\<username>\AppData\Local\Temp\Low\SessionWin32k\1750\conhost.exe File name: conhost.exe
Size: 274.94 KB (274944 bytes)
MD5: 39ac4626bb55759fc9c376e7b33dc0a1
Detection count: 1,033
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Low\SessionWin32k\1750\conhost.exe
Group: Malware file
Last Updated: July 9, 2022
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\olm.exe File name: olm.exe
Size: 358.4 KB (358400 bytes)
MD5: 02306dc6be32bcdc6d3ff742058d2ead
Detection count: 351
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\olm.exe
Group: Malware file
Last Updated: June 27, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Chromium Updating.exe File name: Chromium Updating.exe
Size: 711.16 KB (711168 bytes)
MD5: cdf251106ab7dea1ae4ce307f4e352ff
Detection count: 311
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Chromium Updating.exe
Group: Malware file
Last Updated: August 6, 2020
%TEMP%\winlogon.exe File name: winlogon.exe
Size: 50.17 KB (50176 bytes)
MD5: b97636a52caf65b54463c541ec00310e
Detection count: 122
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 10, 2010
%APPDATA%\Microsoft\Internet Explorer\pb32.exe File name: pb32.exe
Size: 215.55 KB (215552 bytes)
MD5: af13ce721832a1082f8e46f4e6c52002
Detection count: 108
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Internet Explorer
Group: Malware file
Last Updated: November 12, 2010
%USERPROFILE%\Local Settings\Application Data\gprxatijf\utfudmhuqiw.exe File name: utfudmhuqiw.exe
Size: 245.76 KB (245760 bytes)
MD5: aa00a17e2650629f63afd4bc0cbb63af
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data\gprxatijf
Group: Malware file
Last Updated: October 7, 2010
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\nvc.exe File name: nvc.exe
Size: 752.64 KB (752640 bytes)
MD5: a1bcc11cc6e4e76108b212efc8643770
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\nvc.exe
Group: Malware file
Last Updated: June 26, 2020
%WINDIR%\smss.exe File name: smss.exe
Size: 28.16 KB (28160 bytes)
MD5: c966e4745bac88d0bb69c47fe46c2fae
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: October 5, 2010
%TEMP%\save_0_in.exe File name: save_0_in.exe
Size: 223.73 KB (223736 bytes)
MD5: 92b9363efc32b3cc5008b4d19a44ce4b
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: June 22, 2012
%SystemDrive%\48a5ab98\48a5ab98.exe File name: 48a5ab98.exe
Size: 253.95 KB (253952 bytes)
MD5: 1c9493b8aaffd624c97c37834200d610
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\48a5ab98
Group: Malware file
Last Updated: April 3, 2015
%APPDATA%\Origin\update.vbe File name: update.vbe
Size: 79.36 KB (79360 bytes)
MD5: 5e06e0e3b0cd13f86ad2dc9b274282d9
Detection count: 56
Mime Type: unknown/vbe
Path: %APPDATA%\Origin
Group: Malware file
Last Updated: August 30, 2020
%APPDATA%\Microsoft\svchost.exe File name: svchost.exe
Size: 105.47 KB (105472 bytes)
MD5: 5601b6e886ebe1a23dc36bf0b0f82a20
Detection count: 45
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft
Group: Malware file
Last Updated: November 4, 2010
%LOCALAPPDATA%\KBDHEOR2.dll File name: KBDHEOR2.dll
Size: 77.31 KB (77312 bytes)
MD5: 691fe9536ebb6477460a9167b9836a9e
Detection count: 37
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: November 12, 2010
c:\Users\<username>\appdata\local\tallidle\aoqinvirtual\michll_seder.dll File name: michll_seder.dll
Size: 268.8 KB (268800 bytes)
MD5: 7e2f97d9d78ce67e3e41fccc51a6e4d4
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: c:\Users\<username>\appdata\local\tallidle\aoqinvirtual\michll_seder.dll
Group: Malware file
Last Updated: February 8, 2022
%ALLUSERSPROFILE%\RuqoHugxa\IejcEnye.xnr File name: IejcEnye.xnr
Size: 301.05 KB (301056 bytes)
MD5: 5fadc590216e4a92143b598b6aed210b
Detection count: 13
Mime Type: unknown/xnr
Path: %ALLUSERSPROFILE%\RuqoHugxa
Group: Malware file
Last Updated: December 30, 2014
4131500ab1d4e9f620e5101e51d98587 File name: 4131500ab1d4e9f620e5101e51d98587
Size: 453.95 KB (453956 bytes)
MD5: 4131500ab1d4e9f620e5101e51d98587
Detection count: 12
Group: Malware file
14.exe File name: 14.exe
Size: 135.16 KB (135168 bytes)
MD5: 417494bee98a01655f9f13d4d5efb12f
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%USERPROFILE%\csrss.exe File name: csrss.exe
Size: 107.52 KB (107520 bytes)
MD5: 111d8b5d91c8cee13aa7e0cc03624070
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: November 9, 2010
%APPDATA%\mssend2\svcnost.exe File name: svcnost.exe
Size: 133.12 KB (133120 bytes)
MD5: 190fce0279df0aa997a010a2bf991212
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\mssend2
Group: Malware file
Last Updated: December 20, 2010

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathscaalqtw.exeRegexp file mask%ALLUSERSPROFILE%\sqldump.exe%APPDATA%\b[NUMBERS].exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\[RANDOM CHARACTERS].com.url%APPDATA%\Origin\update.vbe%APPDATA%\Stanfind.exe%APPDATA%\vpn gui.exe%LOCALAPPDATA%\Microsoft\Windows\Symbols\wvfilters.sys%TEMP%\nvc.exe%TEMP%\system.exe%TEMP%\winsrvcs32.exe

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\windrivgr 19.7%LOCALAPPDATA%\DsHcaJnIIz

Related Posts

One Comment

Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.