Malware

Win32/Kryptik.GJMN (file analysis)

Malware Removal

The Win32/Kryptik.GJMN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GJMN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GJMN?


File Info:

crc32: F8FCB92B
md5: 31563f2e6b92193775c5757dc670ffac
name: 31563F2E6B92193775C5757DC670FFAC.mlw
sha1: 2179f2a626735051fbf9cb73325f4b830ff6afa9
sha256: f2c82f47301b53fbbf197bacf7548ac81d340a31afbf0242b4b18c848397f451
sha512: 0a7c7bb478d6cafeffb64036283856af717a1140e389531325bcb64f10497d53c45841eace5369ee178f1823f7f688fb526c1e0e38409bbcc886d0df56dcf85a
ssdeep: 24576:OPA2Vfg+ETJTN2+WdVTrderlnc4G3PwQVAwe7:OzgI9TBerFVG3pd2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

internalname: Newspaperwoman
companyname: Gentles Inferiorities
legaltrademarks: Peavey Intemperately
productversion: 58.65.43.948
productname: Cuckoo
Translation: 0x0724 0x0000

Win32/Kryptik.GJMN also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005396aa1 )
LionicTrojan.Win32.Blocker.j!c
ALYacGen:Variant.Ursu.262109
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1540080
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.c86898c0
K7GWTrojan ( 005396aa1 )
Cybereasonmalicious.e6b921
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJMN
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.ldjn
BitDefenderGen:Variant.Ursu.262109
NANO-AntivirusTrojan.Win32.Blocker.fhvosq
MicroWorld-eScanGen:Variant.Ursu.262109
TencentMalware.Win32.Gencirc.114d3769
Ad-AwareGen:Variant.Ursu.262109
SophosMal/Generic-S
ComodoMalware@#1qzakrpffmiaj
BitDefenderThetaGen:NN.ZexaF.34170.3uW@aiQuhzki
McAfee-GW-EditionGenericRXHL-XX!31563F2E6B92
FireEyeGeneric.mg.31563f2e6b921937
EmsisoftGen:Variant.Ursu.262109 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.iup
Antiy-AVLTrojan/Generic.ASMalwS.271F316
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.D3FFDD
GDataGen:Variant.Ursu.262109
AhnLab-V3Malware/Win32.Generic.C2638629
McAfeeGenericRXHL-XX!31563F2E6B92
MAXmalware (ai score=100)
VBA32TrojanRansom.Blocker
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.97 (RDMK:9ilVnjfU/0fWz06Mr/DkXQ)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GJIS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GJMN?

Win32/Kryptik.GJMN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment