Malware

Win32/Kryptik.GJLN removal instruction

Malware Removal

The Win32/Kryptik.GJLN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GJLN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to modify proxy settings
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GJLN?


File Info:

crc32: 128682F0
md5: aa7b843c4a45eb4a6cfca0a8f6656984
name: AA7B843C4A45EB4A6CFCA0A8F6656984.mlw
sha1: b14531e201001379f17dd02b9eada86fbfbcee9e
sha256: 314c0f6aa9f61f793164599b2ab6bde8ecad802d1f7bf43769bbab9e792cf06b
sha512: 52db73f74fb64757b3b9308f654873af48dc71b5f52a12bb8c90f1e2141c9a2dba8a051002650e94aa0f4896632b9d22a9323393eab74ddfa3de5c45ce098f19
ssdeep: 6144:8KCGxnB4Vw8Nup0INfWFBRNYPkqOyMGtjiIDPSTSrfOSJaZ:2ygzup0INybNgndtWI5rDJa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

internalname: Semioblivious
legaltrademarks: Feinschmeckers
comments: Amphiboles
productversion: 42.90.60.971
filedescription: Prestige Hostlers
originalfilename: Bestially
Translation: 0x0799 0x0258

Win32/Kryptik.GJLN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24344
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31125166
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.126393
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.0859ea20
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c4a45e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJLN
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.lcwe
BitDefenderTrojan.GenericKD.31125166
NANO-AntivirusTrojan.Win32.Blocker.fjnioj
MicroWorld-eScanTrojan.GenericKD.31125166
TencentMalware.Win32.Gencirc.114cf58b
Ad-AwareTrojan.GenericKD.31125166
SophosMal/Generic-S
ComodoApplication.Win32.IStartSurf.C@6f890e
BitDefenderThetaGen:NN.ZexaF.34142.qqW@aiQb7zci
TrendMicroTROJ_FRS.VSN1EG18
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.aa7b843c4a45eb4a
EmsisoftTrojan.GenericKD.31125166 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.irw
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1121474
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2714454
MicrosoftTrojan:Win32/Occamy.C31
ArcabitTrojan.Generic.D1DAEEAE
GDataTrojan.GenericKD.31125166
AhnLab-V3Trojan/Win32.Blocker.C2634317
Acronissuspicious
McAfeeArtemis!AA7B843C4A45
MAXmalware (ai score=87)
VBA32BScope.Trojan.Fuerboos
PandaTrj/RnkBend.A
TrendMicro-HouseCallTROJ_FRS.VSN1EG18
RisingTrojan.Generic@ML.92 (RDML:4F8evzEkHYL8IxwrQ1qJ6Q)
YandexTrojan.GenAsa!prVNM33elQQ
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GJHR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GJLN?

Win32/Kryptik.GJLN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment