Malware

Win32/Kryptik.AXOT information

Malware Removal

The Win32/Kryptik.AXOT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AXOT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.AXOT?


File Info:

name: 8FE197EEEF5A7345EFE5.mlw
path: /opt/CAPEv2/storage/binaries/c38f8a81b677d207a25847d88aac17ba12ccce68086f1039782a1f33ed4d1bb0
crc32: 70DCAD2F
md5: 8fe197eeef5a7345efe53999b8d83cf5
sha1: a795e2255c6f240def1263d48fd64fcc4d85937b
sha256: c38f8a81b677d207a25847d88aac17ba12ccce68086f1039782a1f33ed4d1bb0
sha512: 53be869541a12ea569f4f6a43fbe7d9fbf47cb28024727d633d69b5117cd1c135e1071b5bca9f28d3d5a41ba8d1dc6a19a76096551c639773c2abe9e95febbfb
ssdeep: 6144:LNFK+BxA6fk2S09Edo9iDBy2ZMrcFNrLhgI+A:LN0+XA6fk25x9wBymMrcfrL9+A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0242267CEC27A6CF5FA85B6D1943C1A32277763E9B277470019393638976133036CAA
sha3_384: f7e844da6eeaae555fcf435f7dd7a394a1f41b7dc778b51da659497fe5ed6d91ed991517a289085ed2f5674f56fe4cb3
ep_bytes: 60be00a06f008dbe0070d0ff5789e58d
timestamp: 2011-03-28 05:37:49

Version Info:

FileDescription: Evy Giworu Jyti
FileVersion: 6, 8, 1
LegalTrademarks: Wicubyb Opigy Vycymy Rylyxed Uga Ewasami Vanaxu Ysexino Onut Vyjo
LegalCopyright: © 2000 Uwakero Yri. Ipa Wose Matin.
ProductName: Ogyjo
Translation: 0x0409 0x04b0

Win32/Kryptik.AXOT also known as:

LionicTrojan.Win32.Generic.lt5d
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2977
MicroWorld-eScanGen:Variant.Jaiks.5538
FireEyeGeneric.mg.8fe197eeef5a7345
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Jaiks.5538
CylanceUnsafe
VIPRETrojan.Win32.Zbot.dx (v)
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0040f3931 )
AlibabaTrojan:Win32/Kryptik.0d6ffe37
K7GWTrojan ( 0040f3931 )
Cybereasonmalicious.eef5a7
BitDefenderThetaGen:NN.ZexaF.34212.mm0@aC6XyuC
VirITTrojan.Win32.Generic.AMMD
CyrenW32/A-4f779d06!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AXOT
TrendMicro-HouseCallTROJ_FAKEAV.SMJ9
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Jaiks.5538
NANO-AntivirusTrojan.Win32.Zbot.bskoev
SUPERAntiSpywareTrojan.Agent/Gen-PWS
AvastWin32:Malware-gen
TencentWin32.Trojan.Spy.Egon
Ad-AwareGen:Variant.Jaiks.5538
EmsisoftGen:Variant.Jaiks.5538 (B)
ComodoTrojWare.Win32.Spy.Zbot.JZFT@4wtvuc
ZillyaTrojan.Zbot.Win32.113189
TrendMicroTROJ_FAKEAV.SMJ9
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.dc
SophosMal/Generic-R + Troj/Zbot-EJN
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Jaiks.5538
JiangminTrojanSpy.Zbot.cyaj
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Zbot.EB.291
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.43EAF9
KingsoftWin32.Heur.KVMH004.a.(kcloud)
ArcabitTrojan.Jaiks.D15A2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
McAfeeGenericRXAA-AA!8FE197EEEF5A
VBA32BScope.Trojan.MTA.0661
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojanSpy.Zbot!WwAZcD1+Xlw
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.AY!tr
AVGWin32:Malware-gen
PandaGeneric Malware

How to remove Win32/Kryptik.AXOT?

Win32/Kryptik.AXOT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment