Malware

How to remove “Win32/Kryptik.GMBA”?

Malware Removal

The Win32/Kryptik.GMBA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GMBA virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GMBA?


File Info:

crc32: 1BB90218
md5: d9fc7ba43adc5bfde00469bc46260a64
name: D9FC7BA43ADC5BFDE00469BC46260A64.mlw
sha1: d9e8940fd9d8a936e3ffd941627a2ebec5d51a6f
sha256: de1d93dbb9fe925b3f7a7b502a134977bd92be5ca00cc2279c3cc0ea6b71a293
sha512: 462d6ab45d3c31af1b21949e533e0eb85aa272f6980c62bce7ec0a18529f072049fcafdaa304635a6473b52beeb658fd4f135ee8dc1c2da69ec8053062746b23
ssdeep: 24576:lfPr7sIQo/CqHUEiPs4rZJctAxzjel2dkY8AvrbWvcO4zsAvIM:lfXsMzHUfwAT6vcO4zsAQM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GMBA also known as:

K7AntiVirusTrojan ( 0053feb81 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3758
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Ser.Symmi.286
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.14334
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Katusha.193a9cbf
K7GWTrojan ( 0053feb81 )
Cybereasonmalicious.43adc5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMBA
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Symmi.286
NANO-AntivirusTrojan.Win32.Ekstak.fjsaqf
MicroWorld-eScanGen:Variant.Ser.Symmi.286
TencentMalware.Win32.Gencirc.10ba4906
Ad-AwareGen:Variant.Ser.Symmi.286
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34170.0rX@aKc8e8ki
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-FME!D9FC7BA43ADC
FireEyeGeneric.mg.d9fc7ba43adc5bfd
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.uit
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28C26C0
MicrosoftSoftwareBundler:Win32/ICLoader
ZoneAlarmTrojan-PSW.Win32.Azorult.gen
GDataGen:Variant.Ser.Symmi.286
AhnLab-V3PUP/Win32.ICLoader.R241490
Acronissuspicious
McAfeePacked-FME!D9FC7BA43ADC
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!XePcX23MEso
IkarusPUA.FileTour
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]

How to remove Win32/Kryptik.GMBA?

Win32/Kryptik.GMBA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment