Malware

Should I remove “Win32/Kryptik.AXID”?

Malware Removal

The Win32/Kryptik.AXID is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AXID virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Creates a hidden or system file
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.AXID?


File Info:

name: 465466353D03FA8A4B4E.mlw
path: /opt/CAPEv2/storage/binaries/1c7beba685a0586b57cd69990c5d4c29e428548ed64f97b2fa1376643f40e08a
crc32: 0E323546
md5: 465466353d03fa8a4b4e76595101addc
sha1: cf7d434b0ddd10caf12cd6c4804dd526c8f795a1
sha256: 1c7beba685a0586b57cd69990c5d4c29e428548ed64f97b2fa1376643f40e08a
sha512: 6250c99dcfabe8627156f84852822eb2efc15c12487084afafc632f6ddbc065365a3c729faf47455641308727e3249377994997d6ffe6c46dc6873d197020eaf
ssdeep: 6144:hsUTxSfmskOe7sCN1iOYhElS4ytBxuAZb:hsxfnzeIXhElYuAB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194549DF08590603AD89482F05C52AD3A8E1DEC665BA85DEB1259FCD23FB31C487EE51F
sha3_384: 06e2509909ac345487901d7d0c86c018b17e5c289b7891307cf4f8c29736bf3ab87aa131fbeb62828266688345df7426
ep_bytes: 558bec5155c745fc3bdb0000c745fc3b
timestamp: 2013-03-22 18:17:49

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectPlay Voice Test
FileVersion: 5.03.2600.5512 (xpsp.080413-0845)
InternalName: dpvsetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dpvsetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.03.2600.5512
Translation: 0x0409 0x04b0

Win32/Kryptik.AXID also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Razy.778691
FireEyeGeneric.mg.465466353d03fa8a
CAT-QuickHealTrojanDropper.Gepys.A
McAfeePacked-AM!465466353D03
CylanceUnsafe
ZillyaTrojan.ShipUp.Win32.1158
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.53d03f
BaiduWin32.Trojan.Agent.eq
VirITTrojan.Win32.Generic.QGQ
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXID
APEXMalicious
ClamAVWin.Trojan.Shipup-4
KasperskyTrojan.Win32.ShipUp.boo
BitDefenderGen:Variant.Razy.778691
NANO-AntivirusTrojan.Win32.ShipUp.bqolrw
AvastWin32:Gepys-J [Trj]
TencentMalware.Win32.Gencirc.10b0d384
Ad-AwareGen:Variant.Razy.778691
ComodoTrojWare.Win32.Kryptik.AYQE@4wlbfl
DrWebTrojan.Siggen5.1870
VIPREGen:Variant.Razy.778691
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.AutoRun.dh
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/ZAccess-CG
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1KR2NFM
JiangminTrojan/ShipUp.aai
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.217
ArcabitTrojan.Razy.DBE1C3
MicrosoftTrojan:Win32/ShipUp.DSK!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Shipup.R58811
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34582.ry2@aOhO8afi
ALYacGen:Variant.Razy.778691
MAXmalware (ai score=81)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesTrojan.FakeMS.ED
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!inOEU/QgBGA
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYUW!tr
AVGWin32:Gepys-J [Trj]
PandaTrj/Hexas.HEU
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.AXID?

Win32/Kryptik.AXID removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment