Malware

Win32/Kryptik.GJVE (file analysis)

Malware Removal

The Win32/Kryptik.GJVE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GJVE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:50000
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
greatoric.com
manismay.com

How to determine Win32/Kryptik.GJVE?


File Info:

crc32: B1FF8870
md5: 31ad468d57c02a0928c9dd80e906363d
name: 31AD468D57C02A0928C9DD80E906363D.mlw
sha1: e9c0dc61c51aa8d5e5ce93f2295321460416c569
sha256: 8af3e5358e8a4363a48a1fdbe0cf6fe58e0120cad0f170c3af6063e95d9c2677
sha512: 090ed0f815ec2e604c2687a2f63b1f5df1de5a776899a03c3aea7ff5c1eb094ffbcbcec4099b05c5ace2589be8cb5e655bb798f297bf377aa3839eb44100fff3
ssdeep: 12288:HTquyZQFNM1/6468toc6lZVGfynGPSYuDlaE2:HTq5QA1MQoclb6lF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 4, 6, 3861, 5324
CompanyName: Behind Came
LegalTrademarks: Footnotice Little
ProductVersion: 4, 6, 3861, 5324
FileDescription: Footnotice Little
OriginalFilename: hotsound.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GJVE also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005345201 )
Elasticmalicious (high confidence)
DrWebTrojan.IcedID.12
CAT-QuickHealTrojan.Tiggre.ZZ4
ALYacGen:Heur.Mint.Zard.53
MalwarebytesMalware.AI.1732840454
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 005345201 )
Cybereasonmalicious.1c51aa
CyrenW32/S-d9f3cfc7!Eldorado
SymantecTrojan.IcedID
ESET-NOD32a variant of Win32/Kryptik.GJVE
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.53
NANO-AntivirusTrojan.Win32.IcedID.feawqo
MicroWorld-eScanGen:Heur.Mint.Zard.53
TencentMalware.Win32.Gencirc.10c9452c
Ad-AwareGen:Heur.Mint.Zard.53
SophosML/PE-A
ComodoTrojWare.Win32.IcedID.CC@7qblyh
BitDefenderThetaGen:NN.ZexaF.34294.Fq0@ay8fWfli
TrendMicroPossible_HPGen-31
McAfee-GW-EditionGenericRXFU-JX!31AD468D57C0
FireEyeGeneric.mg.31ad468d57c02a09
EmsisoftGen:Heur.Mint.Zard.53 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.IcedID.bu
AviraHEUR/AGEN.1124576
Antiy-AVLTrojan/Generic.ASMalwS.2697D20
MicrosoftTrojan:Win32/Skeeyah.A!rfn
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Heur.Mint.Zard.53
AhnLab-V3Malware/Win32.Generic.C2566697
McAfeeGenericRXFU-JX!31AD468D57C0
MAXmalware (ai score=83)
VBA32BScope.TrojanBanker.IcedID
PandaTrj/GdSda.A
TrendMicro-HouseCallPossible_HPGen-31
RisingTrojan.Generic@ML.92 (RDML:L8/pUmBsPtbaCw29TVy/Gw)
YandexTrojan.PWS.IcedID!894ERwTG+oQ
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.414bea!tr
AVGWin32:Malware-gen

How to remove Win32/Kryptik.GJVE?

Win32/Kryptik.GJVE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment