Malware

Should I remove “Win32/Kryptik.GIOE”?

Malware Removal

The Win32/Kryptik.GIOE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GIOE virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Detects the presence of Wine emulator via function name
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a registry key

How to determine Win32/Kryptik.GIOE?


File Info:

name: 9255417E33F1B75824C7.mlw
path: /opt/CAPEv2/storage/binaries/65cd7f398eee4c9200be3bba7641a461dcd12707d43ec3c527c2c310459cf3ac
crc32: E68FFFA6
md5: 9255417e33f1b75824c7ccef5eb8b608
sha1: 9e66a2d0a0608c794c4d5a242cdc3d59a695fe67
sha256: 65cd7f398eee4c9200be3bba7641a461dcd12707d43ec3c527c2c310459cf3ac
sha512: 4f7a3ab8f01e1652e10ae7eb5bc0c2ad8e3bec5d2a1b1bf63ecd879b4acd58ee8b37b88f6de2512a0d4937652b7acb5262e96c934ac6cf39e0840bff47884330
ssdeep: 3072:wOVXa70sSwqibCRA57QHetJ7wyijOcdzo3/z0EI33BqavEtAtFFFFFFFw:wOLyweX7wyij7zW/z0N
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1481449137150D472E48F04B0446A8AE05A68ED313B65CDEB7BA1FE7E6E306D0DA3671B
sha3_384: 4e5a16debc95e84c90bd50786ce17f3fd744cc196bd5918ec15189a92f61e820bb601138c88a9bb57a77d4a33ad31dbe
ep_bytes: e8c07e0000e978feffff2da403000074
timestamp: 2018-07-06 21:27:21

Version Info:

CompanyName: Taloon Energy Saving Machine
FileDescription: Taloon Energy Saving Machine
FileVersion: 2.04.001
InternalName: Taloon Energy Saving Machine
LegalCopyright: Taloon Energy Saving Machine
OriginalFilename: Taloon Energy Saving Machine
ProductName: Taloon Energy Saving Machine
ProductVersion: 2.04.001
Translation: 0x0409 0x04b0

Win32/Kryptik.GIOE also known as:

BkavW32.FamVT.RazyNHmC.Trojan
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Proxy2.287
MicroWorld-eScanGen:Variant.Symmi.89008
FireEyeGeneric.mg.9255417e33f1b758
ALYacGen:Variant.Symmi.89008
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
K7AntiVirusTrojan ( 005372361 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 005372361 )
Cybereasonmalicious.e33f1b
BitDefenderThetaGen:NN.ZexaF.34084.mq0@aisjRMc
SymantecPacked.Generic.521
ESET-NOD32a variant of Win32/Kryptik.GIOE
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Symmi.89008
NANO-AntivirusTrojan.Win32.Proxy2.ivimwl
SUPERAntiSpywareTrojan.Agent/Gen-Injector
AvastWin32:Malware-gen
RisingTrojan.Generic@ML.100 (RDML:PviXeWGF13AWjZ9u06SKuA)
Ad-AwareGen:Variant.Symmi.89008
SophosMal/Generic-R + Mal/Lethic-L
ComodoMalware@#dii9yo7ft7pz
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXGB-QV!9255417E33F1
EmsisoftGen:Variant.Symmi.89008 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Crypt.aww
AviraHEUR/AGEN.1115228
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.26E2886
MicrosoftTrojan:Win32/Occamy.C65
ViRobotTrojan.Win32.Agent.203776.P
GDataGen:Variant.Symmi.89008
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Kryptik.C2606017
Acronissuspicious
McAfeeGenericRXGB-QV!9255417E33F1
VBA32Trojan.Fuerboos
MalwarebytesTrojan.Crypt
APEXMalicious
TencentWin32.Trojan.Mikey.Hrer
YandexTrojan.GenAsa!tPSkI+0Pwhk
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GJPK!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.GIOE?

Win32/Kryptik.GIOE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment