Malware

What is “Win32/Kryptik.GIJO”?

Malware Removal

The Win32/Kryptik.GIJO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GIJO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Danish
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Win32/Kryptik.GIJO?


File Info:

crc32: 74BA7D0B
md5: 9c829d9acc153d3435a0058ffb4d413b
name: 9C829D9ACC153D3435A0058FFB4D413B.mlw
sha1: 843b8c66f89fee828293117a08f470b9bdc678bf
sha256: 500752e8e06a3100854d68675e0a66cbcef46384331678c537a593e8de88db07
sha512: da290395b284d87c3837a34fd5fb30adbd9823170f37f07c435aad39a3422999b939f3bc6187f3ac7c5ad96f08fa0dfe87b2d5f24da48b5ba9bc30663ecb98d5
ssdeep: 6144:Ert9ZpCb0jLxvywdKnXQ9Q2sEqFtQ1Gpb2p:I9ZpqsdPdKnX0s9tQ1GYp
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GIJO also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Packed.Gandcrab-6552923-4
FireEyeGeneric.mg.9c829d9acc153d34
CAT-QuickHealTrojan.Chapak.ZZ6
McAfeeGenericRXGG-UT!9C829D9ACC15
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 005362211 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 005362211 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/S-07a576a7!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Predator.71542192
NANO-AntivirusTrojan.Win32.NeutrinoPOS.feqnsp
ViRobotTrojan.Win32.GandCrab.Gen.A
AegisLabTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
TencentMalware.Win32.Gencirc.10b4cff1
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoTrojWare.Win32.Chapak.GI@7q43kg
F-SecureHeuristic.HEUR/AGEN.1106540
DrWebTrojan.PWS.Stealer.23807
ZillyaTrojan.GandCrypt.Win32.487
TrendMicroRansom_GANDCRAB.SMALY-3
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
MaxSecureRansomeware.GandCrypt.Gen
SophosML/PE-A + Mal/Agent-AUL
IkarusTrojan.Win32.Predator
JiangminTrojan.Banker.NeutrinoPOS.eq
AviraHEUR/AGEN.1106540
Antiy-AVLTrojan[Banker]/Win32.NeutrinoPOS
MicrosoftTrojan:Win32/Predator.PVD!MTB
ArcabitTrojan.Ransom.GandCrab.Gen.2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
VBA32BScope.TrojanRansom.GandCrypt
ALYacTrojan.Ransom.GandCrab.Gen.2
MAXmalware (ai score=100)
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GIJO
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-3
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!gLvEHrQaVTw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/GenKryptik.CNAR!tr
BitDefenderThetaGen:NN.ZexaF.34590.vuX@a4RDrBpG
AVGFileRepMalware
Cybereasonmalicious.acc153
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.637

How to remove Win32/Kryptik.GIJO?

Win32/Kryptik.GIJO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment