Malware

About “Win32/Kryptik.GJCY” infection

Malware Removal

The Win32/Kryptik.GJCY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GJCY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

all.fingersleep.bid
none.coalrate.men

How to determine Win32/Kryptik.GJCY?


File Info:

crc32: E1F48A20
md5: 65ea5dd5abf5c940afa782ca4fb102d9
name: 65EA5DD5ABF5C940AFA782CA4FB102D9.mlw
sha1: c0b1f1c9166bcd0185d05b146092398a3b0815db
sha256: 15aa0390f2a40112fd3df8e6ebe442751edbe7127d437b2ac61857fbb61dcb8b
sha512: 72c08ae43e859263b508e7d2994024d170aff9e91c6abdbf5d1838affc5f29f6bec3581b385da2d15e827e1bc7cb7fff462120ab3536058883f2e759309420b1
ssdeep: 24576:I+MPjqR3wlo0d5j5Ze0QO8BG2eFE8aenyRke2sq9:I+MbP5SO90leneq9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Atue
InternalName: ICUDAHATTEKA.EXE
FileVersion: 2.8.2.10
CompanyName: xa9Atue
ProductName: ICUDAHATTEKA
ProductVersion: 2.8.2.10
OriginalFilename: icudahatteka.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.GJCY also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053ba2f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
CynetMalicious (score: 100)
ALYacApplication.Agent.DDT
CylanceUnsafe
ZillyaTool.Agent.Win32.25123
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaAdWare:Win32/StartSurf.c34212b9
K7GWTrojan ( 0053ba2f1 )
Cybereasonmalicious.5abf5c
CyrenW32/Kryptik.FDS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJCY
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.brze
BitDefenderApplication.Agent.DDT
NANO-AntivirusRiskware.Win32.StartSurf.ffsauy
MicroWorld-eScanApplication.Agent.DDT
TencentMalware.Win32.Gencirc.10c9762a
Ad-AwareApplication.Agent.DDT
SophosGeneric PUA MA (PUA)
ComodoTrojWare.Win32.Injector.ZRA@54s8j9
BitDefenderThetaGen:NN.ZexaF.34170.Kr0@aKldvjfi
McAfee-GW-EditionBehavesLike.Win32.Packed.tm
FireEyeGeneric.mg.65ea5dd5abf5c940
EmsisoftApplication.Agent.DDT (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.cfo
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.2712D11
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitApplication.Agent.DDT
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataApplication.Agent.DDT
AhnLab-V3PUP/Win32.StartSurf.R232924
Acronissuspicious
McAfeePacked-FKC!65EA5DD5ABF5
MAXmalware (ai score=70)
VBA32BScope.Adware.StartSurf
MalwarebytesAdware.DLAssistant.Generic
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexTrojan.GenAsa!KxT/YBxhbDc
IkarusPUA.Win32.Prepscram
FortinetW32/Kryptik.GJAJ!tr
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GJCY?

Win32/Kryptik.GJCY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment