Malware

What is “Win32/Kryptik.GJIC”?

Malware Removal

The Win32/Kryptik.GJIC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GJIC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GJIC?


File Info:

crc32: C2AF04C7
md5: 714b0821720658b1192e100e9f2f0b0f
name: 714B0821720658B1192E100E9F2F0B0F.mlw
sha1: 033796cf83a75c1af9a63b33ea5686d120f3f511
sha256: 6f12bbdc08670378dce0c28e019cc269194befe1285d67ae990887b536096204
sha512: df931f4f14e2ce17901d11a2adb2a85a5d8dc458ded0a11243d539e6ebb80472edb3dc2ac592e5e9eb5fa646a98201bb7d12dc8cb32f1bc9f34507da8b98884d
ssdeep: 6144:2ZcpLiSW5jDPrUMscRJdlgqV9zk6kfhMS4PZSHmsxnaQY7AXLg:McpiSePYQdCqfgpMS2sxna1Is
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (c) Huimin
InternalName: MinorityProcesses
FileVersion: 5.3.43.5
CompanyName: Huimin
PrivateBuild: 5.3.43.5
Comments: Sitting Allcatins Objects
ProductName: MinorityProcesses
ProductVersion: 5.3.43.5
FileDescription: Sitting Allcatins Objects
OriginalFilename: MinorityProcesses
Translation: 0x0409 0x04b0

Win32/Kryptik.GJIC also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005392961 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop17.32228
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Crysis
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.133532
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Crysis.ali1020005
K7GWTrojan ( 005392961 )
Cybereasonmalicious.172065
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJIC
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.DelShad.ggw
BitDefenderGen:Variant.Ransom.Scarab.43
NANO-AntivirusTrojan.Win32.Kryptik.fhmjwh
MicroWorld-eScanGen:Variant.Ransom.Scarab.43
Ad-AwareGen:Variant.Ransom.Scarab.43
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaE.34690.vmLfayrsEsji
TrendMicroTROJ_GEN.R002C0WEK21
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.714b0821720658b1
EmsisoftGen:Variant.Ransom.Scarab.43 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.etb
WebrootW32.Malware.Gen
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.2723453
KingsoftWin32.Heur.KVM099.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ransom.Scarab.43
AegisLabTrojan.Multi.Generic.4!c
GDataGen:Variant.Ransom.Scarab.43
AhnLab-V3Malware/Win32.Generic.C2642036
Acronissuspicious
McAfeeArtemis!714B08217206
MAXmalware (ai score=100)
VBA32TrojanRansom.Foreign
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WEK21
RisingRansom.Crysis!1.B3A4 (CLOUD)
YandexTrojan.Foreign!Ll6fQKGJYC4
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.GJIC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GJIC?

Win32/Kryptik.GJIC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment