Malware

Win32/Kryptik.GEAH information

Malware Removal

The Win32/Kryptik.GEAH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GEAH virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:50000
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

divorough.com
percalabia.com

How to determine Win32/Kryptik.GEAH?


File Info:

crc32: DD2B24AF
md5: abb1282561e477c7dbc1187bcc25ef63
name: ABB1282561E477C7DBC1187BCC25EF63.mlw
sha1: 39a2658964c33939f198e411d7d357b49df3f23f
sha256: 13a72319bcd18c656e5b57f72f7248a61ceb835e5fd6e1c33499e664a8d27059
sha512: 5b736f3156e74ce2b1e8c795970caa7b351ab43d354d564d33507d9aba2144172925e25b0aa1a414182ae746426432c39df9d108d5669f1f6091c29d8c215fa7
ssdeep: 3072:TOXlE9IEm+dfSJua1kxgDWFyWInoICAxkalDCZtqNtpIWfBt3kJf7NWDX:qXMmwqNkx0WdnAWzZI/pj3kl7NWD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GEAH also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Chapak.tpnx
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.4208
ClamAVWin.Malware.Generickdz-6726589-0
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0053305e1 )
K7AntiVirusTrojan ( 0053305e1 )
CyrenW32/S-63ae5de8!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GEAH
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Yakes.eyqvfj
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentMalware.Win32.Gencirc.10ce49ab
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-S + Mal/GandCrab-D
ComodoTrojWare.Win32.Magniber.B@7k5lm3
BitDefenderThetaGen:NN.ZexaF.34088.muW@a4FOU!ai
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_GANDCRAB.SMALY-3
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.abb1282561e477c7
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.zbr
AviraHEUR/AGEN.1117310
eGambitUnsafe.AI_Score_92%
Antiy-AVLTrojan/Generic.ASMalwS.24DA04B
MicrosoftTrojan:Win32/Tiggre!rfn
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.4
AhnLab-V3Win-Trojan/Gandcrab02.Exp
Acronissuspicious
McAfeeGenericRXAA-AA!ABB1282561E4
MAXmalware (ai score=97)
VBA32BScope.Trojan.Pushdo
MalwarebytesMalware.AI.866423606
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-3
RisingTrojan.Generic@ML.90 (RDML:7KZB++QnfGZaUZF4E22srA)
YandexTrojan.GenAsa!6l/sKj4lFHI
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/RanumBot.J!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCEpsA

How to remove Win32/Kryptik.GEAH?

Win32/Kryptik.GEAH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment