Malware

Win32/Kryptik.GJNV (file analysis)

Malware Removal

The Win32/Kryptik.GJNV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GJNV virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GJNV?


File Info:

crc32: 53A75634
md5: cb23803c3dc2cce619b2999f973c7b78
name: CB23803C3DC2CCE619B2999F973C7B78.mlw
sha1: 60b47e065257fee7e022e236c56ec31a3cbae901
sha256: 1dd520a63be927ccb861c25788e35ee9001c5098d51a8c45ecba69a09207cd3a
sha512: 30a13080d114b260a6dcb63cb63b464660f01f2ba93cb1ae2b2a2969d3b1bec08bd59aabf1b6083398dc30845f34ed31ba8996c1876fd2557a47b05f28c972cc
ssdeep: 1536:aQ+cX2S8cP2Spig75jryJ8jpxTZkak4dGuD32oilXYby09XN:P+qrig0J8fTyakoGuD3ilXYby05N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: telnet.exe
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Microsoft Telnet Client
OriginalFilename: telnetc.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GJNV also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00539a4c1 )
LionicHacktool.Win32.Krap.lKMc
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.56935
ClamAVWin.Dropper.Bunitu-9893704-0
ALYacTrojan.Mint.Zamg.O
MalwarebytesMalware.AI.1730890973
ZillyaTrojan.Yakes.Win32.69183
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 00539a4c1 )
Cybereasonmalicious.c3dc2c
CyrenW32/Agent.CET.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJNV
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Yakes.xgcn
BitDefenderTrojan.Mint.Zamg.O
NANO-AntivirusTrojan.Win32.Kryptik.fhpyfg
MicroWorld-eScanTrojan.Mint.Zamg.O
TencentMalware.Win32.Gencirc.10cc06d4
Ad-AwareTrojan.Mint.Zamg.O
SophosMal/Generic-S + Mal/Cerber-AM
ComodoTrojWare.Win32.Yakes.ADC@7vd6j1
BitDefenderThetaGen:NN.ZexaF.34266.tq1@aSXTeKci
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.SHADE.SMB.hp
FireEyeGeneric.mg.cb23803c3dc2cce6
EmsisoftTrojan.Mint.Zamg.O (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.NetStream.hw
AviraHEUR/AGEN.1117922
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2804F75
ArcabitTrojan.Mint.Zamg.O
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
GDataTrojan.Mint.Zamg.O
AhnLab-V3Trojan/Win32.Yakes.R237311
Acronissuspicious
McAfeeTrickbot-FRDP!CB23803C3DC2
MAXmalware (ai score=99)
VBA32BScope.TrojanProxy.Bunitu
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.SHADE.SMB.hp
RisingTrojan.Kryptik!1.B397 (CLASSIC)
YandexTrojan.GenAsa!ZEESzy/x0qw
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GLWT!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GJNV?

Win32/Kryptik.GJNV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment