Malware

Win32/Kryptik.DXKY removal tips

Malware Removal

The Win32/Kryptik.DXKY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DXKY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.DXKY?


File Info:

name: E738F53AA941FF072645.mlw
path: /opt/CAPEv2/storage/binaries/cdee2ac932d0aab69feff2e84c29db102884a0400e55bc2d270b4705d92d274c
crc32: D88D4D2A
md5: e738f53aa941ff072645ec326deaa141
sha1: 370590f5820b9866e56f4eaf181b888cc212ba77
sha256: cdee2ac932d0aab69feff2e84c29db102884a0400e55bc2d270b4705d92d274c
sha512: 133a3cb3db4e86d6bce4362496556eda09c6ec835d86ad62c8d867a3106b0417077e7b225a8fa5c00bfb595e525876d5940331bc4a7de6ca8ea23dc494320683
ssdeep: 6144:Eck18MipfIUaQYu8tbUhjX/Tvf8MJYFW8jb/HVbdsifRe9+kH:EX8Djadu82jX/THmxr1bBGLH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8A4E100B6D1C073E99A417D8D06CF39A26B74892F367AD37BDC068E1B262D39B36741
sha3_384: 4a8967340d5afd322e493f37fadcf4eca5b85c7113edec0daa9ea59fff47254905a8d42470184bf66e68d586c462e426
ep_bytes: e822690000e917feffff8b44240433c9
timestamp: 2015-09-01 11:09:14

Version Info:

0: [No Data]

Win32/Kryptik.DXKY also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.13690
MicroWorld-eScanGen:Variant.Zusy.435893
FireEyeGeneric.mg.e738f53aa941ff07
CAT-QuickHealTrojan.GenericPMF.S30400603
SkyhighBehavesLike.Win32.Generic.gm
McAfeeGenericRXVR-AZ!E738F53AA941
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.435893
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0057101a1 )
K7GWSpyware ( 0057101a1 )
Cybereasonmalicious.5820b9
BitDefenderThetaGen:NN.ZexaF.36744.CuY@a0fuSlj
VirITTrojan.Win32.Banker1.BQVI
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DXKY
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.Shifu.pef
BitDefenderGen:Variant.Zusy.435893
NANO-AntivirusTrojan.Win32.Banker1.fkcapg
SUPERAntiSpywareTrojan.Agent/Gen-Banker
AvastWin32:BankerX-gen [Trj]
TencentTrojan.Win32.Spy.ta
EmsisoftGen:Variant.Zusy.435893 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
ZillyaTrojan.Kryptik.Win32.1533751
Trapminemalicious.high.ml.score
SophosTroj/Shiz-BS
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.18XLRYN
JiangminTrojan.Generic.cuvox
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan[Banker]/Win32.Shifu
XcitiumWorm.Win32.Gamarue.IC@7xv6jz
ArcabitTrojan.Zusy.D6A6B5
ZoneAlarmHEUR:Trojan-Banker.Win32.Shifu.pef
MicrosoftWorm:Win32/Gamarue!rfn
VaristW32/Shiz.AE.gen!Eldorado
AhnLab-V3Worm/Win.Generic.R509254
Acronissuspicious
VBA32TScope.Malware-Cryptor.SB
TACHYONBanker/W32.Shifu.458752
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Gamarue!8.13B (TFE:5:BXtcUbWu9KR)
YandexTrojanSpy.Shiz!iZLKyOnu9zE
IkarusTrojan.Win32.Shifu
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.DZLG!tr
AVGWin32:BankerX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.DXKY?

Win32/Kryptik.DXKY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment