Trojan

What is “Trojan.Crypt.GH”?

Malware Removal

The Trojan.Crypt.GH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.GH virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Crypt.GH?


File Info:

name: 842A68DFD0C67C9C9F50.mlw
path: /opt/CAPEv2/storage/binaries/f68952c82e222d258b29c78a969cd5497426378464296ed3fc75955903ce0f30
crc32: 5550D429
md5: 842a68dfd0c67c9c9f502da16303368a
sha1: afa147e0e0d0f8357a2c567e030001034d1693d5
sha256: f68952c82e222d258b29c78a969cd5497426378464296ed3fc75955903ce0f30
sha512: b65226912af06fc23ba653e49d5a58c39827da3cbde36d80c0d2ea4ce9aba5785716558372e5966fca034e73816f847722fb4fd4d822645237677099b320ce66
ssdeep: 192:YChCcgoZxA1fNWNYxLpzGQoJ97NmK7qV7Lg69lA9WjWW4E:NRvA1wiRpSQoJ9BmK7qZPlUWjWW
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1A322AF4B77F9552AF9F756B20E378714422B74106E3EDA4CEB8C118A78F10248A31777
sha3_384: adb93afe8528250b2eb8b3897f00752d5caf0ef7324ac435de78ffde345cd3e580f65edea3d64cc2568928483a0aae9a
ep_bytes: 807c2408010f85b901000060be008000
timestamp: 2008-04-22 19:58:24

Version Info:

Comments: Net Messages DLL
CompanyName: Microsoft Corporation
FileDescription: Net Messages DLL
FileVersion: 5.5.5.2
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.5.5.2
LegalCopyright: © Microsoft Corporation. All rights reserved.
Translation: 0x0409 0x04b0

Trojan.Crypt.GH also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Crypt.GH
FireEyeTrojan.Crypt.GH
SkyhighBehavesLike.Win32.Fake.lc
McAfeeArtemis!842A68DFD0C6
VIPRETrojan.Crypt.GH
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Dorando.9d029156
K7GWTrojan ( 0002119d1 )
K7AntiVirusTrojan ( 0002119d1 )
BitDefenderThetaGen:NN.ZedlaF.36804.amSfaudP0zbi
VirITTrojan.Win32.Agent_r.DJ
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/TrojanProxy.Dorando.B
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Glukelira.gen
BitDefenderTrojan.Crypt.GH
NANO-AntivirusTrojan.Win32.Glukelira.buxzq
AvastWin32:Globan [Trj]
TencentWin32.Trojan-Proxy.Glukelira.Ocnw
EmsisoftTrojan.Crypt.GH (B)
F-SecureTrojan-Proxy:W32/Dorando.A
DrWebTrojan.Maby.1864
IkarusTrojan.Win32.Agent
JiangminTrojanProxy.Glukelira.ezr
WebrootW32.Malware.Gen
VaristW32/Dorando.B.gen!Eldorado
AviraTR/Crypt.FKM.Gen
Antiy-AVLTrojan[Proxy]/Win32.Glukelira
KingsoftWin32.HeurC.KVMH008.a
XcitiumMalware@#wq1ytnv3mlj8
ArcabitTrojan.Crypt.GH
ZoneAlarmTrojan-Proxy.Win32.Glukelira.gen
GDataTrojan.Crypt.GH
GoogleDetected
AhnLab-V3Trojan/Win32.Glukelira.R10186
VBA32BScope.Trojan.Agent
ALYacTrojan.Crypt.GH
TACHYONTrojan-Proxy/W32.Glukelira.32768.AB
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Win32.Generic.12904B0D (C64:YzY0OllWCw/qX2KG)
YandexTrojan.Crypt!s2ImajSVVgM
MAXmalware (ai score=100)
FortinetW32/Glukelira.NEG!tr
AVGWin32:Globan [Trj]
DeepInstinctMALICIOUS
alibabacloudProxyTool:Win/Dorando.B

How to remove Trojan.Crypt.GH?

Trojan.Crypt.GH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment