Malware

Should I remove “Win32/Kryptik.GBIH”?

Malware Removal

The Win32/Kryptik.GBIH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GBIH virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GBIH?


File Info:

crc32: 28B61C02
md5: 7b98da8d5afea8b21ea369e631bec037
name: 7B98DA8D5AFEA8B21EA369E631BEC037.mlw
sha1: 70b83746647cfa85bbf280b80030b1ff365a8f75
sha256: 1a1e39f6d5038ad69a8aeea53a0d4c1e8b90da6f974c39ae3967527db11bb6dd
sha512: 7a5d876c41f3726ff4dde46f6f1179d02399b9609c587cad04b8ce026a83a6a3f1244d2eb509691da5a987c0658df3dc2e30b5ae7d3d9fbd2971719e9ce9b740
ssdeep: 49152:eEfn3n06cXPGct4YXTe5VhKFjA2+KC+lRR:b37EPGctI5wjA2+KjfR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2017 Piriform Ltd
InternalName: sd.exe
FileVersion: 6.33.0.6130
CompanyName: SudoSoft
ProductName: CCleaner
ProductVersion: 6.33.0.6130
FileDescription: CCleaner
OriginalFilename: sd.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GBIH also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052331a1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2635
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacApplication.Bundler.ICLoader.5.Gen
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1345976
SangforSuspicious.Win32.Save.a
K7GWTrojan ( 0052331a1 )
Cybereasonmalicious.d5afea
CyrenW32/S-6f9cd638!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GBIH
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.Bundler.ICLoader.5.Gen
NANO-AntivirusTrojan.Win32.InstallCube.ewsyqb
MicroWorld-eScanApplication.Bundler.ICLoader.5.Gen
TencentMalware.Win32.Gencirc.10ba5a63
Ad-AwareApplication.Bundler.ICLoader.5.Gen
SophosMal/Generic-S
ComodoTrojWare.Win32.Crypt.B@7o6bny
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXEO-DM!7B98DA8D5AFE
FireEyeGeneric.mg.7b98da8d5afea8b2
EmsisoftApplication.FileTour (A)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.dsuf
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.23ECB6C
MicrosoftPUADlManager:Win32/InstallCube
ArcabitApplication.Bundler.ICLoader.5.Gen
GDataWin32.Packed.Kryptik.KW
AhnLab-V3PUP/Win32.ICLoader.R217745
Acronissuspicious
McAfeeGenericRXEO-DM!7B98DA8D5AFE
MAXmalware (ai score=77)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.MegaDowl
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!Je9diD4rCqY
IkarusTrojan-Downloader.Agent
MaxSecurePacked.Packed.WIN32.Katusha.gen_212008
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GBIH?

Win32/Kryptik.GBIH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment