Malware

Win32/Kryptik.GEPL removal tips

Malware Removal

The Win32/Kryptik.GEPL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GEPL virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Anomalous binary characteristics

Related domains:

ec2-52-57-16-9.eu-central-1.compute.amazonaws.com
illumex.ai
apps.identrust.com

How to determine Win32/Kryptik.GEPL?


File Info:

crc32: 3AF59678
md5: 710e4d3a9575069e4ac12b3e5e3413ad
name: 710E4D3A9575069E4AC12B3E5E3413AD.mlw
sha1: 98a3953c29138ecdf0c0dd4250e48748a60bcb17
sha256: 24bd19d8bb5b2d799aea21f9dd9d77414d399da8995452bdbe9142ff060a31df
sha512: 9a52c95dc2207687c3ca4cc33a1e3e96e2f1f36514aa95a0a9f438efce2a043daf353ed852640e8dc760afc635eaf835dc1f2dc9849350ebd389eddf97e4ad94
ssdeep: 49152:eo3tfNunNHL0ET8WfATyvcO4z1Pq3eAQTjPwy:P3tfoNVAGvcOuPq3eAIjIy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductName: McAfee Safe Connect
ProductVersion: 1.0
FileDescription: McAfee Safe Connect Installer
FileVersion: 1.0
CompanyName: McAfee
Translation: 0x0409 0x04b0

Win32/Kryptik.GEPL also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00533b5a1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3282
CynetMalicious (score: 100)
ALYacTrojan.Mint.Zamg.J
CylanceUnsafe
ZillyaTrojan.Katusha.Win32.52703
K7GWTrojan ( 0052b8be1 )
Cybereasonmalicious.a95750
CyrenW32/Kryptik.CNC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GEPL
APEXMalicious
AvastWin32:AdwareSig [Adw]
ClamAVWin.Dropper.Icloader-6553203-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderTrojan.Mint.Zamg.J
NANO-AntivirusTrojan.Win32.InstallCube.eyzzel
MicroWorld-eScanTrojan.Mint.Zamg.J
TencentMalware.Win32.Gencirc.114ceb18
Ad-AwareTrojan.Mint.Zamg.J
SophosMal/Generic-S + Mal/BadCert-Gen
ComodoApplication.Win32.ICLoader.GS@84429a
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.Win32.ICLOADER.SM
McAfee-GW-EditionPacked-VJ!710E4D3A9575
FireEyeGeneric.mg.710e4d3a9575069e
EmsisoftApplication.AdFile (A)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.dvnz
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.250BC2B
MicrosoftPUADlManager:Win32/InstallCube
GDataTrojan.Mint.Zamg.J
AhnLab-V3PUP/Win32.ICLoader.R223029
Acronissuspicious
McAfeePacked-VJ!710E4D3A9575
MAXmalware (ai score=99)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
TrendMicro-HouseCallPUA.Win32.ICLOADER.SM
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
YandexTrojan.GenAsa!mTpOT3qUEhs
IkarusPUA.FileTour
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GEPL?

Win32/Kryptik.GEPL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment