Malware

Win32/Kryptik.AMFX malicious file

Malware Removal

The Win32/Kryptik.AMFX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AMFX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.AMFX?


File Info:

name: 2361E6BF409FE53EBB61.mlw
path: /opt/CAPEv2/storage/binaries/18849fe1d655a39c45e2099ae7a4a77741b68fb0423ccbe89ca884fb86d2528d
crc32: 7F737483
md5: 2361e6bf409fe53ebb61a195021dc807
sha1: 284bf9f560715d478c5b5cadff10f290ac3e2987
sha256: 18849fe1d655a39c45e2099ae7a4a77741b68fb0423ccbe89ca884fb86d2528d
sha512: 2b99a3bb48fb428220860036542f0af1e1e35e844e397396c4d85b055e324fb8f25a0dc86ed53bdaee0bd8ea11d75b4b223ec6365199eb1555c8e4a0cd9b075c
ssdeep: 3072:Ie6lXYMmjunHTOT4+UM9sQOvDyBPzGN/GZ2tu/TG4cxhILl+Z8bSnLq+0znD:8Ajuzr+UMIbu7GN/lcS4cxhTnLqjn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111040150A192C86BEAD6C6F5A5B6CDCD87681111D3515A8363806E7EB0353C8BC3F27F
sha3_384: 8bdd3968c8fc7fd0f105d9ef07e701bd821d2ae1836dac3b615f0e839a3a4568d2da29b27f829e9f3dd7fc743344ad87
ep_bytes: 558bec6aff6840834000683449400064
timestamp: 2012-09-13 23:48:18

Version Info:

0: [No Data]

Win32/Kryptik.AMFX also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.1392
ClamAVWin.Spyware.Zbot-9840421-0
McAfeePWS-Zbot.gen.anx
Cylanceunsafe
ZillyaTrojan.Zbot.Win32.76401
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f0751 )
K7GWTrojan ( 0040f0751 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Panda.CZD
CyrenW32/S-23d18c8b!Eldorado
ESET-NOD32a variant of Win32/Kryptik.AMFX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.ywir
BitDefenderGen:Variant.Symmi.1392
NANO-AntivirusTrojan.Win32.Zbot.bblutt
AvastWin32:Spyware-gen [Spy]
TencentMalware.Win32.Gencirc.115848a8
EmsisoftGen:Variant.Symmi.1392 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.PWS.Panda.2005
VIPREGen:Variant.Symmi.1392
TrendMicroTSPY_MALCOL_BK084361.TOMC
McAfee-GW-EditionPWS-Zbot.gen.anx
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2361e6bf409fe53e
SophosML/PE-A
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Symmi.1392
JiangminTrojanSpy.Zbot.cces
WebrootW32.Rogue.Gen
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan[Spy]/Win32.Zbot
XcitiumTrojWare.Win32.Kryptik.AMFXA@4vl4ht
ArcabitTrojan.Symmi.D570
ViRobotTrojan.Win32.A.Zbot.188416.BO
ZoneAlarmTrojan-Spy.Win32.Zbot.ywir
MicrosoftPWS:Win32/Zbot!CI
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36164.lqW@aannDdji
ALYacGen:Variant.Symmi.1392
MAXmalware (ai score=84)
VBA32BScope.TrojanSpy.Zbot
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_MALCOL_BK084361.TOMC
RisingMalware.Undefined!8.C (TFE:5:BxiTpmw8byP)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4529124.susgen
FortinetW32/Zbot.EVPV!tr
AVGWin32:Spyware-gen [Spy]
Cybereasonmalicious.f409fe
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.AMFX?

Win32/Kryptik.AMFX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment