Malware

About “Win32/Kryptik.AXUY” infection

Malware Removal

The Win32/Kryptik.AXUY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AXUY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings

How to determine Win32/Kryptik.AXUY?


File Info:

name: 79A92BBD203C57DF7E76.mlw
path: /opt/CAPEv2/storage/binaries/d24fbd031b2d9cf1234a024b70e7c17f1b2164102b94959b5f32f5acf7424b3a
crc32: 86378C64
md5: 79a92bbd203c57df7e76e041a2b2242f
sha1: 0940cc9fbf231055cbdb0f4d163c72d7d30b026e
sha256: d24fbd031b2d9cf1234a024b70e7c17f1b2164102b94959b5f32f5acf7424b3a
sha512: 5283a708776df8b2100a2585a4359600c7747d58f3b798aae4d87ae421b1e83c8a3d4f38df14194768652ffdb71cb820cba353de216b87d7bdf5d7e4312c1505
ssdeep: 6144:8Qkte0N3bYeKw2Dido9g1Suu1nwtcsA9wr9hbXLIvWBbmuA5Pwf:8W0hz2g1SV1nwtcsCUhbXLIvqKuA+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18B84120B0D8415B5FC6619352E7F893D8A93C1CD00C6E5A74496BCA33EF1311FA62ABB
sha3_384: 502199a48bad33e6374851d39fe70b9de645f9f4cb2f8bf063edc9e33b042adae25c220d2014ed5bb9dff6eecdd9323e
ep_bytes: 6a00598db11831400083ee6d8b46ffc1
timestamp: 2013-01-23 18:06:12

Version Info:

0: [No Data]

Win32/Kryptik.AXUY also known as:

MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.79a92bbd203c57df
CAT-QuickHealTrojan.Urausy.C
McAfeeFake-SecTool!79A92BBD203C
CylanceUnsafe
VIPRETrojan.VIZ.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.d203c5
VirITTrojan.Win32.Generic.AZE
CyrenW32/SuspPack.EX.gen!Eldorado
SymantecPacked.Generic.402
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AXUY
APEXMalicious
ClamAVWin.Packed.Urausy-9754886-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.FakeAV.brmtwo
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:LockScreen-UK [Trj]
Ad-AwareTrojan.VIZ.Gen.1
ComodoTrojWare.Win32.Kryptik.AYL@4wdu8z
DrWebTrojan.Packed.196
TrendMicroTROJ_FAKEAV.SMCC
McAfee-GW-EditionBehavesLike.Win32.VirRansom.fc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Zbot-KR
SentinelOneStatic AI – Malicious PE
GDataTrojan.VIZ.Gen.1
AviraTR/ResCrypt.A
Antiy-AVLTrojan/Generic.ASMalwS.55
ArcabitTrojan.VIZ.Gen.1
MicrosoftRogue:Win32/Winwebsec
TACHYONTrojan/W32.FakeAV.398848.AA
AhnLab-V3Trojan/Win32.Tepfer.R59682
BitDefenderThetaGen:NN.ZexaF.34806.yqW@ayURu8bi
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=81)
VBA32Heur.Trojan.Hlux
TrendMicro-HouseCallTROJ_FAKEAV.SMCC
RisingTrojan.Generic@AI.100 (RDML:K2/6F1zqlKLnyjyWjus/bw)
YandexTrojan.GenAsa!ViD8OEzivTA
IkarusVirus.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.X!tr
AVGWin32:LockScreen-UK [Trj]
PandaAdware/SystemTool
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.AXUY?

Win32/Kryptik.AXUY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment