Malware

Win32/Kryptik.AXRD information

Malware Removal

The Win32/Kryptik.AXRD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AXRD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.AXRD?


File Info:

name: 2B2F8F638C366B732112.mlw
path: /opt/CAPEv2/storage/binaries/573d9ab55e9158c99e53e757e8d4e9f2b3aa4b5dbf539b73433da9f390f4893e
crc32: E8416B8E
md5: 2b2f8f638c366b732112fc469ac5ae5e
sha1: 900969fbcdf9a36eacbcab626a33a9a07cad1916
sha256: 573d9ab55e9158c99e53e757e8d4e9f2b3aa4b5dbf539b73433da9f390f4893e
sha512: 7bde4a06e8842c283ea55e7b25d090acab6a29b7afd16cfa9e507558614e7f5706d53f0e4f99af694c8bb40c720260081053bf46f51d2aab3044ec7b62ab0f2d
ssdeep: 12288:bBXXXXXXXXXAXX7hx6UhqXYZ1Xok3IpaZQ10hSnA/Qz5wYGfc:ax6Uoy1j3IsprI7Gfc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17DC4F0DF8157C323ECC66038BBA580F3967D3B64EE83968A40D0EB44AE5C9587724D6D
sha3_384: b570c64d05f4c61546cd0fdab70906e3da1be86b2f7ef923f4824df62c5eca4ee491769890969832ea43f996decccc79
ep_bytes: 558bec5155c745fc5f010000c745fc5f
timestamp: 2013-03-29 06:28:14

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Win32/Kryptik.AXRD also known as:

BkavW32.AIDetectMalware
AVGWin32:Agent-ARAC [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.Redirect.140
MicroWorld-eScanGen:Variant.Ransom.TorrentLocker.92
SkyhighBehavesLike.Win32.PWSZbot.hc
McAfeeGenericRXCQ-PF!2B2F8F638C36
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.4663256
SangforTrojan.Win32.Save.a
Cybereasonmalicious.38c366
BitDefenderThetaGen:NN.ZexaF.36802.Ky3@aChdnwoc
VirITTrojan.Win32.Generic.ACYF
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AXRD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Redirect-6055402-0
KasperskyTrojan.Win32.ShipUp.bpo
BitDefenderGen:Variant.Ransom.TorrentLocker.92
NANO-AntivirusTrojan.Win32.ShipUp.bqoadx
AvastWin32:Agent-ARAC [Trj]
TencentTrojan.Win32.Shipup.xe
EmsisoftGen:Variant.Ransom.TorrentLocker.92 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan.Agent.eq
VIPREGen:Variant.Ransom.TorrentLocker.92
TrendMicroTROJ_KRYPTK.SMAD
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2b2f8f638c366b73
SophosMal/Zbot-FG
SentinelOneStatic AI – Malicious PE
JiangminTrojan.ShipUp.egs
VaristW32/Zbot.JC.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Generic
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Zbot!pz
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Ransom.TorrentLocker.92
ZoneAlarmTrojan.Win32.ShipUp.bpo
GDataWin32.Trojan.PSE.NZ7PLO
GoogleDetected
AhnLab-V3Trojan/Win.ShipUp.R639660
Acronissuspicious
VBA32BScope.Trojan.ShipUp
ALYacGen:Variant.Ransom.TorrentLocker.92
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SMAD
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.WebSpoof.Gen.AL
IkarusTrojan.Win32.ShipUp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYTK!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.AXRD?

Win32/Kryptik.AXRD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment