Malware

Win32/Kryptik.GEED removal tips

Malware Removal

The Win32/Kryptik.GEED is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GEED virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.virmach.ru
politiaromana.bit
malwarehunterteam.bit
ns2.virmach.ru
gdcb.bit

How to determine Win32/Kryptik.GEED?


File Info:

crc32: 1F811BD1
md5: 8a3e0f2e5a3e59ac198f10abea43b7e1
name: 8A3E0F2E5A3E59AC198F10ABEA43B7E1.mlw
sha1: 95f4b1a56e81e52ce8955f2e1aa2db13427800e5
sha256: 4e85a7bfd0fc516e5f2461488f68194677acefc3c6bc97bdac30702b3b1fd40c
sha512: 74e2a96a8c4eaa6f8af6c6c496c57fdff2d578bf8b4e0521b53dfd83a1d2a09511be9b07a8e25da060913b83ad116f7458d6b91ef915cad643e6d9acb7e01939
ssdeep: 6144:5/t46hainoOboNyNkBVeRRQ1lTaufuobjzUecAak5QH3usJ:5C6h9oOKUaV6RQ1BJbXUecAak5QXusJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GEED also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.8a3e0f2e5a3e59ac
CAT-QuickHealTrojan.Chapak.ZZ5
McAfeeGenericRXEG-WP!8A3E0F2E5A3E
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.753
AegisLabTrojan.Win32.Generic.4!c
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 00532e3d1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWAdware ( 004ea9a61 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Brmon.ZABB-8299
SymantecRansom.Hermes!gen1
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Chapak.eyuavf
ViRobotTrojan.Win32.GandCrab.Gen.A
TencentMalware.Win32.Gencirc.10b2a422
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
TACHYONRansom/W32.GandCrab
SophosMal/Generic-R + Mal/Agent-AUL
ComodoBackdoor.Win32.Quicdy.A@7k4jqu
F-SecureHeuristic.HEUR/AGEN.1121533
DrWebTrojan.Encoder.24828
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.SMLA.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.aiuo
MaxSecureRansomeware.CRAB.gen
AviraHEUR/AGEN.1121533
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftVirTool:Win32/CeeInject.ABL!bit
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.suX@a0ezc2oi
ALYacTrojan.Ransom.GandCrab.Gen.2
MAXmalware (ai score=98)
VBA32Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ZonerTrojan.Win32.68375
ESET-NOD32a variant of Win32/Kryptik.GEED
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
RisingTrojan.Kryptik!1.B09C (CLASSIC)
YandexTrojan.GenAsa!nHqFflcHNJw
IkarusTrojan-Ransom.GandCrab
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.DWPH!tr
AVGWin32:Malware-gen
Cybereasonmalicious.e5a3e5
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.dfd

How to remove Win32/Kryptik.GEED?

Win32/Kryptik.GEED removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment