Malware

Should I remove “Win32/Kryptik.AXL”?

Malware Removal

The Win32/Kryptik.AXL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AXL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

redirector.gvt1.com
r8—sn-bpb5oxu-3c2r.gvt1.com
update.googleapis.com

How to determine Win32/Kryptik.AXL?


File Info:

crc32: 04366062
md5: 07465388d72bc859d0fb7c918d9aad02
name: 07465388D72BC859D0FB7C918D9AAD02.mlw
sha1: 3cc12d0d470f4be4a2fb34c7688bdebb21994b07
sha256: e49a22ab62be4fc9a122539412d60bb8cff1b24b91734404025cdc7405a02998
sha512: 0171db394fccfc012b32790f60fc82d4f0562ccd134cbb120f28799e45a649991bab4316bfe3f2a0d39851831f812d9cd6c118a415f2489f1435c863fbd88c0c
ssdeep: 1536:FckyCSvAhiNiV0I2flDU5A1b6L69Sn+nHAIex:FckyC5his0VSaJWQHq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: tLZC
InternalName: ST26HTuGUSdOt
FileVersion: 9qZG3ZpSwfEsx
CompanyName: 0h7rxtHTTmNrs
ProductName: xrvmYxv5qFA
ProductVersion: 1U54fGMc6KSD
FileDescription: N8y9
OriginalFilename: zKJH12jWWSnTQ

Win32/Kryptik.AXL also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055dd191 )
Elasticmalicious (high confidence)
DrWebTrojan.Packed.21756
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Ransom.A
ALYacGen:Variant.Kazy.27983
CylanceUnsafe
ZillyaTool.FlashApp.Win32.87
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Genasom.e20a523a
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.8d72bc
CyrenW32/Ransom.J.gen!Eldorado
SymantecTrojan.Ransomlock!gen2
ESET-NOD32a variant of Win32/Kryptik.AXL
APEXMalicious
AvastWin32:Mystic
ClamAVWin.Trojan.Ransom-6090
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.27983
NANO-AntivirusRiskware.Win32.FlashApp.faqtbv
MicroWorld-eScanGen:Variant.Kazy.27983
TencentWin32.Trojan-PSW.Flashapp.ctq
Ad-AwareGen:Variant.Kazy.27983
SophosML/PE-A + Mal/EncPk-ADY
ComodoTrojWare.Win32.Trojan.Agent.~xtsa@3ymfaa
BitDefenderThetaGen:NN.ZexaF.34688.du0@aGiGDFkQ
VIPRETrojan.Win32.Ransom.do (v)
TrendMicroRansom_Genasom.R002C0CE521
McAfee-GW-EditionStymic
FireEyeGeneric.mg.07465388d72bc859
EmsisoftGen:Variant.Kazy.27983 (B)
SentinelOneStatic AI – Malicious PE
JiangminHoax.FlashApp.aae
WebrootW32.Trojan.Timer.Gen
AviraBDS/ZeroAccess.Gen7
MicrosoftRansom:Win32/Genasom.DN
ArcabitTrojan.Kazy.D6D4F
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Kazy.27983
TACHYONJoke/W32.FlashApp.60416.C
Acronissuspicious
McAfeeStymic
MAXmalware (ai score=100)
VBA32Trojan.ExpProc.014
PandaGeneric Malware
TrendMicro-HouseCallRansom_Genasom.R002C0CE521
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.FlashApp!F4acQ2+g9rk
IkarusTrojan-Ransom.Timer
FortinetW32/RansomTimer.fam!tr
AVGWin32:Mystic
Paloaltogeneric.ml

How to remove Win32/Kryptik.AXL?

Win32/Kryptik.AXL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment