Virus

What is “Virus.Win32.Crytex.1290”?

Malware Removal

The Virus.Win32.Crytex.1290 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus.Win32.Crytex.1290 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Virus.Win32.Crytex.1290?


File Info:

name: 71FD920380FECB89A088.mlw
path: /opt/CAPEv2/storage/binaries/86426b8fefcba6b0980e1d6b937b0a7cf2cb060ea1948141d593dd4780c9f4f5
crc32: 1FFFF1B1
md5: 71fd920380fecb89a088813836a5534a
sha1: 92f3b27c6f8aafb477d12e043475a385f1e1b673
sha256: 86426b8fefcba6b0980e1d6b937b0a7cf2cb060ea1948141d593dd4780c9f4f5
sha512: 8a6a7bb5e17057040056bb2940f95551bcd2260796ebace89c4290197fbb904010aaca2cd30e8c1b76341c70cf0cc9b938e5cc79e31211ce7b09eda8035e6947
ssdeep: 1536:gBISYgJy1k96ig6Jqe+dxZ1yh/ygDEAG83MXonzq5yk0N6T4nW/X3I+s055Oa37:yYgJys6iglPZ1yxyvZcMO/6T4nIB5B37
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0C38EAB23C8BE12D26CC630BCAE0736FB196C445594431EA9B2FCCD8477ED584567CA
sha3_384: b0ca7a1f8eea9d8cc0c8b0ffa982eeb17eff13988dc7b4c9485f3864f0238eee480b13b434656140b18ca302fea64019
ep_bytes: 609ce8000000005d81ed071040008db5
timestamp: 2001-08-17 20:54:13

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Entertainment Pack Minesweeper Game
FileVersion: 5.1.2600.0 (xpclient.010817-1148)
InternalName: winmine
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: WINMINE.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.0
Translation: 0x0409 0x04b0

Virus.Win32.Crytex.1290 also known as:

BkavW32.GeksoneHQcA.PE
Elasticmalicious (high confidence)
MicroWorld-eScanWin32.Crytex.A
SkyhighBehavesLike.Win32.Pate.cc
VIPREWin32.Crytex.A
K7GWVirus ( 0040f5911 )
K7AntiVirusVirus ( 0040f5911 )
ArcabitWin32.Crytex.A
BaiduWin32.Virus.Crytex.a
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Geksone.B
APEXMalicious
TrendMicro-HouseCallPE_CRYTEX.A
ClamAVWin.Virus.Hublo-1
KasperskyVirus.Win32.Crytex.1290
BitDefenderWin32.Crytex.A
NANO-AntivirusVirus.Win32.Crytex.bzelsx
AvastWin32:Cryte
TencentVirus.Win32.Crytex.a
EmsisoftWin32.Crytex.A (B)
GoogleDetected
F-SecureMalware.W32/Crytex.1290
DrWebWin32.Siggen.15
ZillyaVirus.Geksone.Win32.1
TrendMicroPE_CRYTEX.A
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.71fd920380fecb89
SophosW32/NGVCK-W
IkarusSality.Win32
VaristW32/Crytex.1290
AviraW32/Crytex.1290
Antiy-AVLVirus/Win32.Crytex.1290
Kingsoftmalware.kb.a.1000
XcitiumVirus.Win32.Crytex.1290@4wzy41
MicrosoftVirus:Win32/Geksone.EC!MTB
ZoneAlarmVirus.Win32.Crytex.1290
GDataWin32.Virus.Golem.A
CynetMalicious (score: 100)
BitDefenderThetaAI:Packer.232437BF1F
ALYacWin32.Crytex.A
MAXmalware (ai score=80)
VBA32Virus.Win32.Crytex.1290
Cylanceunsafe
RisingVirus.Geksone!1.AD16 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.W32.Crytex.1290
FortinetW32/Geksone.B
AVGWin32:Cryte
DeepInstinctMALICIOUS
alibabacloudVirus:Win/Hublo.A(dyn)

How to remove Virus.Win32.Crytex.1290?

Virus.Win32.Crytex.1290 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment