Threat Database Trojans Trojan.Kryptik.Y

Trojan.Kryptik.Y

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,041
Threat Level: 80 % (High)
Infected Computers: 792
First Seen: October 24, 2019
Last Seen: May 25, 2026
OS(es) Affected: Windows

The detection of Trojan.Kryptik.Y on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operation, symptoms, and most importantly, steps to remove it from your computer.

What Is Trojan.Kryptik.Y?

Trojan.Kryptik.Y is identified as a Trojan-type threat, which means it is designed to deceive users into installing it on their systems by disguising itself as legitimate software. Once installed, it can cause a variety of problems, including data theft, system crashes, and the installation of additional malware. The name "Trojan.Kryptik.Y" suggests it may have capabilities related to encryption or stealth, but without specific details, it's crucial to approach its removal with a broad strategy to ensure all potential aspects of the threat are addressed.

How Trojan.Kryptik.Y Operates

Trojan.Kryptik.Y, like other Trojans, operates by exploiting the trust of users. It may arrive as an email attachment, a download from an untrusted website, or through exploited vulnerabilities in software. Once inside a system, it can perform a wide range of malicious activities, from spying on the user's activities to downloading and installing other types of malware. The exact operations of Trojan.Kryptik.Y can vary, but its primary goal is to compromise the security and integrity of the infected system for the benefit of its creators.

Symptoms of Infection

Symptoms of a Trojan.Kryptik.Y infection can be subtle and may not immediately indicate the presence of malware. Common signs include slower system performance, frequent crashes, and unusual network activity. Users may also notice that their antivirus software is disabled or that they are being redirected to unwanted websites. In some cases, the presence of the Trojan may not be noticeable at all, making regular system scans crucial for detection.

How to Remove Trojan.Kryptik.Y

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in. To do this, restart your computer and press the key to access your boot menu (this key varies by manufacturer but is often F12, F2, or Del). Select the option to boot into Safe Mode with Networking.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to scan your system for the Trojan and other potential threats. Ensure your tool is updated to the latest version to increase the chances of detecting and removing the malware.
  3. Uninstall Suspicious Programs: Go through your list of installed programs and remove any that you do not recognize or that were installed around the time your system was infected.
  4. Reset Your Browsers: Trojans can often modify browser settings. Resetting browsers like Chrome, Firefox, and Edge to their default settings can help remove unwanted changes and potential additional malware.
  5. Reboot and Re-scan: After taking the above steps, reboot your system to ensure all changes take effect and then perform another scan with your anti-malware tool to confirm that the threat has been removed.

Conclusion

Removing Trojan.Kryptik.Y requires careful and methodical steps to ensure that all components of the malware are eliminated from your system. It's also crucial to adopt preventive measures to avoid future infections, including keeping your operating system and software up to date, using strong antivirus protection, and being cautious when opening email attachments or downloading software from the internet. By following the removal steps outlined and maintaining good computer hygiene, you can protect your system from Trojan.Kryptik.Y and other malware threats.

Analysis Report

General information

Family Name: Trojan.Kryptik.Y
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: da3f2de01bcf2c2686f2c0ca16acb138
SHA1: ddbb93dcae61139ffc96856c71acba92616ae430
SHA256: 4BC293038C4E5382E8C79FB5277CACFA904FD960B7FD5280E80CA8F44A089E16
File Size: 4.11 MB, 4111660 bytes
MD5: e5b57a896142c99aa0e35cff19b67e23
SHA1: f81df6db69c39787cb3dff5b080206b1d32859b1
SHA256: 1AE7F8237A6899A22A107261FB5893CD306BC225FA9C5E17A9C3766C1CB62AD8
File Size: 4.22 MB, 4216656 bytes
MD5: 5dcc52b4b675ec4f5f7119922e6c5f08
SHA1: 54091b63347ed11186667af6ee01901b48a978cc
SHA256: 641840945F2BF122E28A9C06A4691148FF0D37AA0D378898A0993888C22F5412
File Size: 3.46 MB, 3464452 bytes
MD5: 1ba0075c7564ff404b9e23111214cf59
SHA1: 7258dcc57b61957762b334af48c924876be94b71
SHA256: 39E1281692E302D50A2110F15C1ACB255079AF0405A98719017390012DD939DA
File Size: 4.19 MB, 4192412 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • big overlay
  • dll
  • packed
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 6,831
Potentially Malicious Blocks: 2,183
Whitelisted Blocks: 3,099
Unknown Blocks: 1,549

Visual Map

0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 ? ? 0 ? ? 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? x 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 x 0 0 0 0 0 x 0 x ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 ? ? ? 0 ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 0 ? ? ? 0 0 x x 0 0 ? ? ? x x x x x x 0 0 x 0 ? ? ? ? 0 ? ? ? 0 0 ? 0 x 0 0 0 0 0 0 0 0 x x 0 ? ? 0 0 0 0 0 0 ? ? 0 0 x x 0 ? ? 0 0 ? ? 0 x x x ? ? 0 x ? ? ? x 0 0 1 x 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 ? ? x ? ? ? ? ? ? 0 0 0 x 0 0 0 0 0 0 0 0 ? ? 0 x ? 0 ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? 0 0 ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? x ? x ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? x 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 x ? x 0 ? 0 0 ? x x 0 0 ? ? ? ? ? ? ? 0 ? 0 x 0 x ? 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? x ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x ? ? ? ? x ? ? x ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? 0 ? x ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 ? ? ? ? ? 0 x x ? ? ? ? 0 ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 x x x ? ? ? ? x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x ? x ? 0 ? ? ? ? ? ? x ? ? 0 ? ? ? x ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x ? x 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 ? ? 0 0 0 ? ? ? 0 x ? ? ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 x 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 0 ? x 0 ? ? 0 0 ? 0 ? ? 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 0 ? ? 0 0 0 ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? x ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x x ? ? ? ? x x ? x ? ? x ? ? ? ? ? x ? ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? x x x ? ? ? ? ? x ? x ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? x ? ? ? ? x ? ? x ? x x ? ? ? x x ? ? x x x x x ? ? x ? x x ? ? ? ? ? x ? ? ? ? ? 0 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.Y

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ddbb93dcae61139ffc96856c71acba92616ae430_0004111660.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f81df6db69c39787cb3dff5b080206b1d32859b1_0004216656.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\54091b63347ed11186667af6ee01901b48a978cc_0003464452.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7258dcc57b61957762b334af48c924876be94b71_0004192412.,LiQMAxHB

Trending

Most Viewed

Loading...