Malware

Win32/Kryptik.GMRW information

Malware Removal

The Win32/Kryptik.GMRW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GMRW virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GMRW?


File Info:

crc32: 4906334F
md5: bddba5522e047616a8435a89ed1269fe
name: BDDBA5522E047616A8435A89ED1269FE.mlw
sha1: 2806f465e9afa4fd0f014b82dff6363c715b0405
sha256: 883778fb4014100095c426083d92ea12057285a137bdf0d955072f219a387f91
sha512: 82ece51e1eaa91508af5f1f65208271e6d638a37b4eb496851716b79b2ed1ed9f7e10b710f06ed75b6e2416b6287befc5c84032dad040f600c3d9b56f57abe06
ssdeep: 12288:Tjcgz61me3dULvt/yOOA888888888888W88888888888L:fcgsmm2TJb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa92005-2015 IObit
InternalName:
FileVersion: 8.0.0.1327
CompanyName: IObit
LegalTrademarks: IObit
Comments:
ProductName: Initialization Program
ProductVersion: 8.0.0.0
FileDescription: Advanced SystemCare Ultimate
OriginalFilename:
Translation: 0x0409 0x04e4

Win32/Kryptik.GMRW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A4
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
SangforRansom.Win32.Cerber_33.se
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005224381 )
Cybereasonmalicious.22e047
CyrenW32/Locky.H2.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.GMRW
APEXMalicious
AvastWin32:Filecoder-BG [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.GenKryptik.evpvgj
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Generic.Pkhf
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Cerber-K
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaGen:NN.ZexaF.34686.yq1@aq!BHrdj
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM3
McAfee-GW-EditionRansomware-GCQ!BDDBA5522E04
FireEyeGeneric.mg.bddba5522e047616
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1106832
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-GCQ!BDDBA5522E04
MAXmalware (ai score=100)
MalwarebytesPUP.Optional.AdvancedSystemCare
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPCERBER.SM3
RisingTrojan.Kryptik!1.AE9C (CLOUD)
YandexTrojan.GenAsa!/yAoYjrkmaY
IkarusTrojan.Win32.Boaxxe
FortinetW32/Injector.EETM!tr
AVGWin32:Filecoder-BG [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GMRW?

Win32/Kryptik.GMRW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment