Malware

Win32/Kryptik.GBSM information

Malware Removal

The Win32/Kryptik.GBSM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GBSM virus can do?

  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GBSM?


File Info:

crc32: F6F36623
md5: 062edcf21466d6b20540bd060d496b3f
name: 062EDCF21466D6B20540BD060D496B3F.mlw
sha1: 70396d3d319c1be25256c54510dfec1779f74444
sha256: 137a281ce9b6a749f376dcd91a8bdd0eb04c43e2c60019c8d9e85e289f116b25
sha512: 1ae39dba59563c52f61eb232fd6dd1f3b273dfaff55db11ea0f43cfb4d14795a16c5f9426568390314b0fcfb826928a8a65c9adc1f48d9aef1fd485c28fbe375
ssdeep: 3072:NBtSkOfCOTUEKvnfNvmf+Lv7PIfLrhX2YeBTS8lz9OliOVTxmX5IFl1:IkOfCecFvi+Lv70tXN0TSGz9aJ4X4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, ferguhbdhouv
FileVersion: 11.0.0.1
ProductVersion: 11.0.0.1
Translation: 0x0809 0x04b0

Win32/Kryptik.GBSM also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 003e58dd1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.64729
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacTrojan.BRMon.Gen.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 003e58dd1 )
Cybereasonmalicious.21466d
CyrenW32/S-cab1c03c!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GBSM
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.krjl
BitDefenderTrojan.BRMon.Gen.1
NANO-AntivirusTrojan.Win32.Jorik.exdfbt
MicroWorld-eScanTrojan.BRMon.Gen.1
TencentMalware.Win32.Gencirc.114ce2c6
Ad-AwareTrojan.BRMon.Gen.1
SophosMal/Generic-S + Mal/Ransom-FN
ComodoTrojWare.Win32.Jorik.B@7hoiad
BitDefenderThetaGen:NN.ZexaF.34058.mu0@am6v!4bG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.062edcf21466d6b2
EmsisoftTrojan.BRMon.Gen.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Scar.ley
AviraHEUR/AGEN.1126869
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.240F806
MicrosoftVirTool:Win32/Obfuscator.CAP
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataTrojan.BRMon.Gen.1
AhnLab-V3Backdoor/Win32.Androm.R217878
Acronissuspicious
McAfeeGeneric.cyg
MAXmalware (ai score=98)
VBA32BScope.TrojanRansom.Blocker
MalwarebytesTrojan.MalPack.BMP
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingTrojan.Generic@ML.100 (RDML:rXwftYe/Lq+xEw47XlRrwg)
YandexTrojan.GenAsa!FxskQy9/zog
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GBHF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCkf8A

How to remove Win32/Kryptik.GBSM?

Win32/Kryptik.GBSM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment