Malware

Win32/Kryptik.GCSB information

Malware Removal

The Win32/Kryptik.GCSB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GCSB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GCSB?


File Info:

crc32: 5DEB80FE
md5: e3c8a11179c48175dd8a12404568582a
name: E3C8A11179C48175DD8A12404568582A.mlw
sha1: c38106f079dd879c71b9ad1116f7056aef2ea393
sha256: 1e5cd1ffc52306836d1f4094026ee9a492ba5c62f588b850e3ebd7bfc20a64f9
sha512: 215ec202e8839fa3d55c7e9dd42103e02f1e62bf6be21d6566731ca628c65c832e57fa111a975cfa2cc85b8c3cbd6165d6c4064c1889dcb4ba2386736df224f6
ssdeep: 49152:FgN5c/md0TpT7sR3x90KFmaN96e+G+sTyYcStZtR35fHztpWxy6zTE/DpxqRpdi:me2Gpk90RaNQe+GLkKZ7RtUxy6z0pxq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GCSB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00525e501 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.936
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Occamy.A1
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.AdLoad.Win32.23425
SangforTrojan.Win32.Save.a
K7GWTrojan ( 00525e501 )
Cybereasonmalicious.179c48
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GCSB
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:HEUR:AdWare.Win32.DownloadHelper.gen
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusTrojan.Win32.Snojan.exnggo
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.116acae9
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.@tW@aKzC!ppi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VirRansom.vm
FireEyeGeneric.mg.e3c8a11179c48175
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.uave
AviraHEUR/AGEN.1138794
Antiy-AVLTrojan/Generic.ASMalwS.2452FB3
MicrosoftSoftwareBundler:Win32/Dlhelper
ArcabitTrojan.Mint.Zamg.1
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Adware/Win32.AdLoad.R220363
Acronissuspicious
McAfeeGenericRXAA-AA!E3C8A11179C4
MAXmalware (ai score=84)
VBA32Adware.AdLoad
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.99 (RDML:yE8Bn5204sJfGN+rD0erhA)
YandexTrojan.GenAsa!qbdxQiRwwFA
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FWLF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GCSB?

Win32/Kryptik.GCSB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment