Malware

Win32/Kryptik.GCPJ malicious file

Malware Removal

The Win32/Kryptik.GCPJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GCPJ virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key

Related domains:

ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine Win32/Kryptik.GCPJ?


File Info:

crc32: 99FB6162
md5: 4691aa022213c44ccb92cc5c6a791b8b
name: 4691AA022213C44CCB92CC5C6A791B8B.mlw
sha1: 2d4947eb700669467aeb5640ecadebf0c1ce0e61
sha256: 1a2292af2fdc246e3029299d5c246d6ef97f3721b933f504665e893b936db414
sha512: a6e85b8914dc08fad2312f2cb75aa5ddd89b0ad408881d7eebd64e079393d9dfb55ab919b3dc7561c2889efdd5471ceda459b2aeaa12df5cd54aef931de1c94f
ssdeep: 49152:Gz2JrkFIo7ixfV0chPGct4yu5eVhaAk+lR:GzirQIh2KPGctxBlf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GCPJ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2662
ClamAVWin.Packed.Icloader-6952325-0
CAT-QuickHealPUA.IcloaderPMF.S19636164
ALYacGen:Variant.Zusy.398343
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2995088
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 00525a491 )
K7AntiVirusTrojan ( 00528e7f1 )
CyrenW32/S-af6d87b4!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GCPJ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
NANO-AntivirusRiskware.Win32.ICLoader.exlqzx
MicroWorld-eScanGen:Variant.Zusy.398343
TencentMalware.Win32.Gencirc.114cedff
Ad-AwareGen:Variant.Zusy.398343
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GCO@7hwoq2
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
FireEyeGeneric.mg.4691aa022213c44c
EmsisoftApplication.FileTour (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.FileTour.jlk
WebrootW32.Adware.Gen
AviraTR/Crypt.XPACK.Gen2
ArcabitTrojan.Zusy.D61407
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
MicrosoftSoftwareBundler:Win32/ICLoader
AhnLab-V3PUP/Win32.ICLoader.R219807
Acronissuspicious
McAfeePacked-VJ!4691AA022213
MAXmalware (ai score=100)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!hawjt5MU2GE
IkarusPUA.Win32.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGFileRepMalware

How to remove Win32/Kryptik.GCPJ?

Win32/Kryptik.GCPJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment