Malware

Should I remove “Win32/Kryptik.AXRY”?

Malware Removal

The Win32/Kryptik.AXRY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AXRY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP

How to determine Win32/Kryptik.AXRY?


File Info:

name: 409196C515A333C1B8A6.mlw
path: /opt/CAPEv2/storage/binaries/a42f21f7b899467bd16c39807f201fa682bee83a607c9e0774b387b051dbdd2e
crc32: 3D216A41
md5: 409196c515a333c1b8a65eb35c364560
sha1: 39609f203af8fdf4247e2ebdbc09c8249b83545a
sha256: a42f21f7b899467bd16c39807f201fa682bee83a607c9e0774b387b051dbdd2e
sha512: a033423dda651a470da5a8737fc85a0a8a2119a6f4e5e3f3876ca193939e6a21e6b9ef6bc4d46f3147969e33d99e997e6253b57267c3e6e0612f8a464c2b02f7
ssdeep: 24576:QRbkUaz5WxvXW94GPmn0X/IWHS2jvdzx1RvpN:QRbk1lYv6pk0PvXxTJ3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F50523827D250DF6E1909434AAB4B63A023B8CB7DF78CC3193DB6445FDDA792B518839
sha3_384: eb9c8b61d51403083687d8a0ecb2666d979979f0836920a4928ae8c45dc80bc2dfd504f10001599201e393a397aa405c
ep_bytes: 2bf656598db61431400083ee6d8b46ff
timestamp: 2013-01-23 18:06:12

Version Info:

0: [No Data]

Win32/Kryptik.AXRY also known as:

MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.409196c515a333c1
CAT-QuickHealTrojan.Urausy.C
McAfeePWS-Zbot-FASY!409196C515A3
MalwarebytesTrojan.LameShield
VIPRETrojan.VIZ.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
BitDefenderTrojan.VIZ.Gen.1
K7GWTrojan ( 0040f2c01 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Generic.AZB
CyrenW32/SuspPack.EX.gen!Eldorado
SymantecPacked.Generic.402
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXRY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Zbot-9754885-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.ea490607
NANO-AntivirusTrojan.Win32.Tepfer.bnzjkn
RisingStealer.Fareit!8.170 (TFE:2:UEymM6QxZCB)
Ad-AwareTrojan.VIZ.Gen.1
SophosML/PE-A + Mal/Zbot-KR
ComodoTrojWare.Win32.Kryptik.AYL@4wdu8z
DrWebTrojan.PackedENT.24465
TrendMicroTROJ_FAKEAV.SMCC
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
Trapminemalicious.high.ml.score
EmsisoftTrojan.VIZ.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Zbot.EB.293
Antiy-AVLTrojan/Generic.ASMalwS.17F
KingsoftWin32.PSWTroj.Tepfer.hn.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.VIZ.Gen.1
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R59682
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34646.YqW@aafn@afi
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=100)
VBA32OScope.Malware-Cryptor.Hlux.2713
CylanceUnsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_FAKEAV.SMCC
TencentWin32.Trojan.Generic.Gflw
YandexTrojan.GenAsa!BBqswo82lfU
IkarusBackdoor.Win32.Kelihos
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.X!tr
AVGWin32:LockScreen-UJ [Trj]
Cybereasonmalicious.515a33
AvastWin32:LockScreen-UJ [Trj]

How to remove Win32/Kryptik.AXRY?

Win32/Kryptik.AXRY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment