Malware

About “Win32/Kryptik.GMSB” infection

Malware Removal

The Win32/Kryptik.GMSB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GMSB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/Kryptik.GMSB?


File Info:

crc32: 19B80B43
md5: 0cd5e93defa669fcbc33bd734822d692
name: 0CD5E93DEFA669FCBC33BD734822D692.mlw
sha1: faba431e66acb1295b31eae1391b8ae15c8939c9
sha256: 7b8f756bcfce2d0cd48150715d6c52d77e55a3bea52a771736f3d5f4eccd4832
sha512: 39a956599e8d08e9e7447d3abf0b09921cdf3dec86d9c8d11d975b0a4a85f1fd980450651a67f74d339ff9b833f2178c5045fe678425a2a86f8189b91c171a71
ssdeep: 24576:Uum5KJxRU/9hj6dHi/o2mMDwffYgh1OqH1D9+k53tWdu6QjMeROljyRmUhAf/8:Uumk7R4QwmMDwffdhcKd4oWdu6QotVV0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c). All rights reserved. Trimble Navigation Limited
CompanyName: Trimble Navigation Limited
Comments: Brute Boats Listed
ProductName: Figuring
ProductVersion: 6.2.1.8
FileDescription: Brute Boats Listed
Translation: 0x0409 0x04b0

Win32/Kryptik.GMSB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005408101 )
MicroWorld-eScanGen:Variant.Brresmon.126
ALYacGen:Variant.Brresmon.126
MalwarebytesMachineLearning/Anomalous.100%
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Foreign.d8f39e60
K7GWTrojan ( 005408101 )
Cybereasonmalicious.defa66
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMSB
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.odnq
BitDefenderGen:Variant.Brresmon.126
NANO-AntivirusTrojan.Win32.GenKryptik.fkibwt
TencentWin32.Trojan.Foreign.Jmj
Ad-AwareGen:Variant.Brresmon.126
SophosMal/Generic-S
ComodoMalware@#65r6ag7pdo9r
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_HPGen-38
FireEyeGeneric.mg.0cd5e93defa669fc
EmsisoftGen:Variant.Brresmon.126 (B)
AviraHEUR/AGEN.1117382
eGambitUnsafe.AI_Score_82%
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AegisLabTrojan.Win32.Foreign.4!c
GDataGen:Variant.Brresmon.126
AhnLab-V3Malware/Win32.Possible_hpgen.C2818426
McAfeeArtemis!0CD5E93DEFA6
MAXmalware (ai score=88)
VBA32BScope.TrojanSpy.Zbot
PandaTrj/CI.A
TrendMicro-HouseCallPossible_HPGen-38
YandexTrojan.Foreign!DoqBbEKeKu0
IkarusTrojan-Ransom.GandCrab
FortinetW32/Foreign.ODNQ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.39e

How to remove Win32/Kryptik.GMSB?

Win32/Kryptik.GMSB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment