Malware

Win32/Kryptik.DRXQ malicious file

Malware Removal

The Win32/Kryptik.DRXQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DRXQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Win32/Kryptik.DRXQ?


File Info:

name: B1A274BA79FE5E1F15F0.mlw
path: /opt/CAPEv2/storage/binaries/db037ba2589e6d4212de25589cde96a8cb9eade8ae0f8055730d941dc2e2baa0
crc32: 7687E5B3
md5: b1a274ba79fe5e1f15f02deff8528526
sha1: 6ae24dfbafa442dd6d2f0733e1569e430333aaa8
sha256: db037ba2589e6d4212de25589cde96a8cb9eade8ae0f8055730d941dc2e2baa0
sha512: c6cc381fddf4bb0349dd5eb8d64e69665974e6fdb9da075fa08508d536c198cb883cdfc6149116a63612dd044e9a6bf4cb6abf7d115a607a8c5776676d1f3bdb
ssdeep: 768:lhB5prqhHGaAbkOoT6JUU3FIFYrG5RUyGeQUzebaiRFsO/:/dwHGK2UU3FIFYCnJxiRF9/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125430E3166C91261E7768F7DC1B255C266257E623FE5F4CF888132840B73BC6B9F0A1A
sha3_384: c0458b56bd55dc5fff3579c1e4b988a843216eeccc5414af8a7d210107e027ada5e2bf838a2f9b7bcbc1beb30d26c44c
ep_bytes: 558bec6aff689845fe00686039fe0064
timestamp: 2014-06-23 06:11:07

Version Info:

CompanyName: Takenforex
FileDescription: Takenforex
FileVersion: 1.1.2.12
InternalName: Takenforex Internal
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: Takenforex
ProductVersion: 2.1
Translation: 0x0415 0x04e4

Win32/Kryptik.DRXQ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Ipatre.1
ClamAVWin.Malware.Upatre-9939347-0
FireEyeGeneric.mg.b1a274ba79fe5e1f
CAT-QuickHealTrojan.Kadena.B4
ALYacGen:Trojan.Ipatre.1
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.3702985
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005974f21 )
K7AntiVirusTrojan ( 005974f21 )
ArcabitTrojan.Ipatre.1
BitDefenderThetaGen:NN.ZexaF.36164.du2@a8vMg@hG
VirITTrojan.Win32.GenusT.EGHJ
CyrenW32/Kryptik.GDK.gen!Eldorado
SymantecDownloader.Upatre
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.DRXQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderGen:Trojan.Ipatre.1
NANO-AntivirusTrojan.Win32.Upatre.jnwysj
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Downloader.Win32.Waski.16000151
EmsisoftGen:Trojan.Ipatre.1 (B)
BaiduWin32.Trojan.Kryptik.my
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Upatre.10519
VIPREGen:Trojan.Ipatre.1
TrendMicroTROJ_UPATRE.SMX7
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.qt
Trapminesuspicious.low.ml.score
SophosMal/Upatre-V
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.hfste
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Upatre.ehbg
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.BLM@5tms2h
MicrosoftTrojanDownloader:Win32/Upatre
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan.Kryptik.CI
GoogleDetected
AhnLab-V3Trojan/Win32.Upatre.R160586
McAfeeUpatre-FACH!B1A274BA79FE
MAXmalware (ai score=80)
VBA32BScope.Trojan.Upatre
MalwarebytesTrojan.Upatre
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMX7
RisingTrojan.Kryptik!1.A0CC (CLASSIC)
YandexTrojan.GenAsa!+Lxgc5UA2zE
IkarusTrojan.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptic.ABGK!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.DRXQ?

Win32/Kryptik.DRXQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment