Malware

Should I remove “Win32/Kryptik.AKFU”?

Malware Removal

The Win32/Kryptik.AKFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AKFU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP

How to determine Win32/Kryptik.AKFU?


File Info:

name: 8080D5090079C7876211.mlw
path: /opt/CAPEv2/storage/binaries/310ff1496510b8290359a978684252c87bdd4f8b8080491a7cfd36bf8f50a665
crc32: 7C8D8BC3
md5: 8080d5090079c7876211a8089da73893
sha1: 0b2d3a8273485e5e5ce99ece4dea096f69bb0700
sha256: 310ff1496510b8290359a978684252c87bdd4f8b8080491a7cfd36bf8f50a665
sha512: a74b2f793d59eaa4c5885e28f1de73e1700d1e3c48cadfb80aea96288cc41f093d14be380a2ae953e88bdf04df59ce5047bc57a2079a094fb194b9674e90dc40
ssdeep: 12288:paTb/ksqdH1CFDC4Fdlt8DF2bf6UMme19lgyWIx87IyZ1kUBK69Mzt/a4aRt2+Ry:Wbg518FdT8Dcf219dy7IlQmz5aRt25f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E05234AD599A038E06CB8395B4A8E3CC633EC7972C537E14D84F8A91CF856F549F12C
sha3_384: de84d24534957f2249b9707e692817f67f1b585a9f0d03253de8ac9ca0ab85521be438406aef7b2ea81db0833f8b263c
ep_bytes: 6800605700b88c30400066832000ff30
timestamp: 2012-01-18 07:21:34

Version Info:

0: [No Data]

Win32/Kryptik.AKFU also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Dresmon.Gen.1
FireEyeGeneric.mg.8080d5090079c787
CAT-QuickHealFraudTool.Security
McAfeePWS-Zbot.gen.ain
CylanceUnsafe
VIPREGen:Trojan.Dresmon.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040797b1 )
AlibabaTrojan:Win32/LiveSecurity.43986614
K7GWTrojan ( 0040797b1 )
Cybereasonmalicious.90079c
CyrenW32/FakeAlert.VF.gen!Eldorado
SymantecSecShieldFraud!gen7
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AKFU
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-FakeAV.Win32.LiveSecurity.il
BitDefenderGen:Trojan.Dresmon.Gen.1
NANO-AntivirusTrojan.Win32.Kazy.zpwyi
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
AvastWin32:FakeAV-DUO [Trj]
TencentWin32.Trojan-FakeAV.Livesecurity.Zchl
Ad-AwareGen:Trojan.Dresmon.Gen.1
EmsisoftGen:Trojan.Dresmon.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.AJZT@4q80lx
DrWebBackDoor.Slym.767
TrendMicroTROJ_KRYPTK.SMJY
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/FakeAV-FWY
IkarusTrojan-PSW.Win32.Tepfer
GDataGen:Trojan.Dresmon.Gen.1
JiangminTrojan/Generic.angel
WebrootW32.Trojan.Gen
AviraTR/Kazy.J.85803
Antiy-AVLTrojan/Generic.ASMalwS.A77
MicrosoftBackdoor:Win32/Kelihos.F
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R32826
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Trojan.Dresmon.Gen.1
MAXmalware (ai score=100)
MalwarebytesTrojan.LameShield
TrendMicro-HouseCallTROJ_KRYPTK.SMJY
RisingTrojan.Agent!8.B1E (TFE:2:y0GsBDiNvIG)
YandexTrojan.GenAsa!OpUfNEapLR0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AGAI!tr
BitDefenderThetaGen:NN.ZexaF.34646.YqW@aKFHlKkG
AVGWin32:FakeAV-DUO [Trj]
PandaAdware/SystemTool
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.AKFU?

Win32/Kryptik.AKFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment