Malware

Win32/Kryptik.GIMR removal tips

Malware Removal

The Win32/Kryptik.GIMR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GIMR virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Unconventionial language used in binary resources: Estonian
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GIMR?


File Info:

crc32: 7B937AAA
md5: 2ecd37f5627541a0ee16ab59e32e3c46
name: 2ECD37F5627541A0EE16AB59E32E3C46.mlw
sha1: 015f049655257c61d25a9060b9bf922a17440935
sha256: 7b084780afe2b2e21cc8a02745be79d7089d6f24f46d90f51845621c4e8fca32
sha512: aa9e66575a59b8a941b93e4175d2f1a3d85a006a689abee4bfd8924ef3841a8ffee922c33e5f0408e0b23f0573b96803fc04be4f1c644d6d3ac399878689a47c
ssdeep: 12288:vHsgRtE7/6hQrJV+sa5gXCMALGGAITsWm4d:v3EuoJwT3Mx5WVd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, rityutus
Translation: 0x0809 0x04b0

Win32/Kryptik.GIMR also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23950
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ6
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.7261
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Predator.320de221
K7GWTrojan ( 0053bfbf1 )
K7AntiVirusTrojan ( 0053bfbf1 )
CyrenW32/Ransom.KC.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GIMR
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packer.Crypter-6614720-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.NeutrinoPOS.fevkzk
ViRobotTrojan.Win32.GandCrab.349184
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentMalware.Win32.Gencirc.10ba4f88
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-R + Mal/GandCrab-B
ComodoTrojWare.Win32.NeutrinoPOS.CA@7u6vvk
F-SecureHeuristic.HEUR/AGEN.1106533
BitDefenderThetaGen:NN.ZexaF.34608.Hu0@amsacCcI
TrendMicroRansom_GANDCRAB.SMALY-3
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.2ecd37f5627541a0
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.NeutrinoPOS.fc
WebrootW32.Adware.Installcore
AviraHEUR/AGEN.1106533
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Banker]/Win32.NeutrinoPOS
MicrosoftTrojan:Win32/Predator.PVD!MTB
ArcabitTrojan.BRMon.Gen.4
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.4
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
McAfeeGenericRXGB-CH!2ECD37F56275
MAXmalware (ai score=99)
VBA32BScope.TrojanPSW.Stealer
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-3
RisingTrojan.Fuerboos!8.EFC8 (CLOUD)
YandexTrojan.Nymaim!a236suuUM5M
IkarusTrojan.Krypt
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/GenKryptik.CNAR!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.2.5FD1.Malware.Gen

How to remove Win32/Kryptik.GIMR?

Win32/Kryptik.GIMR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment