Malware

Win32/Kryptik.GMCR malicious file

Malware Removal

The Win32/Kryptik.GMCR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GMCR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

Related domains:

trick.matchoatmeal.icu
fuss.wavesfork.online

How to determine Win32/Kryptik.GMCR?


File Info:

name: 4FE1D68358C86EBFF5F1.mlw
path: /opt/CAPEv2/storage/binaries/212f3dc15476bc6515beabf2224da7d7563f96496e67bc543b349b9cce557b6c
crc32: 26365CB6
md5: 4fe1d68358c86ebff5f1204a5420ef0f
sha1: dad988b5c3c2c229372cff79868902b5f18216dd
sha256: 212f3dc15476bc6515beabf2224da7d7563f96496e67bc543b349b9cce557b6c
sha512: 21989b0cae3d70eb449defa1cbecb533d65b2b0703fd17145485a7cdf2b6f74fa9d0ace50ca68058f27ce4c67437e3fd325947ceb7202898c6fa06d2143cb53b
ssdeep: 24576:VULm+EEKr50DDc/u+w8wjeFOQJ/BCyR5CUz0Myrr+XLXHRuf8Es3jQFmwM8:y5EEKF0vgTRCyCIZIA0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFF52369B49286A5E5FD453F0B73ABC9172D2F668C61C443B3A8370D41BE080FB65B93
sha3_384: 40875bf0750b0d607baf58f83423f06f967ec1bf6dcafca41e6e91c68a08829b4edcb7d82e39f4cf59ba4ea245338f0e
ep_bytes: e869110000e9000000006a1468e09f6f
timestamp: 2016-08-10 16:14:06

Version Info:

LegalCopyright: ©Eseabasteada foyshohuseys raneupmaw
ProductName: ETITYVIPASSI
CompanyName: ©Eseabasteada foyshohuseys raneupmaw
InternalName: ETITYVIPASSI.EXE
ProductVersion: 3.9.4.9
FileVersion: 3.9.4.9
OriginalFilename: etityvipassi.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.GMCR also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Symmi.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.4fe1d68358c86ebf
MalwarebytesAdware.IStartSurf
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053ffcb1 )
AlibabaAdWare:Win32/StartSurf.e7658c20
K7GWTrojan ( 0053ffcb1 )
Cybereasonmalicious.5c3c2c
CyrenW32/Kryptik.DIG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMCR
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.StartSurf.dtpe
NANO-AntivirusTrojan.Win32.Vittalia.fjuvde
AvastFileRepMalware
TencentMalware.Win32.Gencirc.114d8a02
ComodoApplicUnwnt@#a90gwgysjhjd
DrWebTrojan.Vittalia.17867
ZillyaAdware.StartSurf.Win32.68267
TrendMicroTROJ_GEN.R002C0PKK21
McAfee-GW-EditionBehavesLike.Win32.Generic.wz
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.dbay
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.28C3211
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotAdware.Startsurf.3497984
CynetMalicious (score: 100)
Acronissuspicious
McAfeePacked-FKC!4FE1D68358C8
VBA32BScope.Adware.Prepscram
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PKK21
RisingTrojan.Kryptik!1.B33C (CLASSIC)
IkarusPUA.Dlhelper
FortinetW32/Kryptik.FSMR!tr
BitDefenderThetaGen:NN.ZexaF.34294.vt0@aKxlUBoi
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Win32/Kryptik.GMCR?

Win32/Kryptik.GMCR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment