Malware

Win32/Kryptik.GNOE (file analysis)

Malware Removal

The Win32/Kryptik.GNOE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GNOE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.GNOE?


File Info:

name: 4F450D1E5DE154569A26.mlw
path: /opt/CAPEv2/storage/binaries/d68024e8a01263390602536996c904d515ed97f3e735693dd4da722ddd3805e5
crc32: 3A2CFF13
md5: 4f450d1e5de154569a2611905970ecdd
sha1: 67a40d0e3152b94ab6a6a959da024473cb9e5f61
sha256: d68024e8a01263390602536996c904d515ed97f3e735693dd4da722ddd3805e5
sha512: ca6baef6c67b498f5fdd894509986f17c1ad25740ac55921c9365f9c0d702287e9ae5f29cff2fe1623a3296c68469c96d4a30e88c83d10e4ef5d640e12272b36
ssdeep: 12288:ZfJ/0FUoC+KifdoboOib+ApU9vNSa3fu2ZBVp+RgLC:h5oC+BfdobkjeLS/2Zc
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T156351230B2E2E0B1C87715796875DEA04D2DBA544F64BE5727890B390E308D1E73EF9A
sha3_384: 9c85848a829fcb3269e58b00110b6dcc14f15703e285bd655168382f70131ac3743baab4c61dd08818615c2bc038df28
ep_bytes: e80d040000e974feffff558bec6a00ff
timestamp: 2019-04-02 10:51:53

Version Info:

0: [No Data]

Win32/Kryptik.GNOE also known as:

LionicRiskware.Win32.Ulise.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.68104
FireEyeGeneric.mg.4f450d1e5de15456
SkyhighBehavesLike.Win32.Generic.tm
McAfeePUP-HMN
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.1615479
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Kryptik.2d29ebdc
K7GWTrojan ( 0054ea9e1 )
K7AntiVirusTrojan ( 0054ea9e1 )
ArcabitTrojan.Generic.D10A08
BitDefenderThetaGen:NN.ZexaF.36744.bvW@aGB7czji
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GNOE
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.68104
NANO-AntivirusTrojan.Win32.Kryptik.foubly
AvastWin32:MWrich-A [Trj]
TencentMalware.Win32.Gencirc.10b0ed7b
EmsisoftTrojan.GenericKDZ.68104 (B)
F-SecureHeuristic.HEUR/AGEN.1317744
VIPRETrojan.GenericKDZ.68104
SophosIStartSurfInstaller (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.deggf
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1317744
Antiy-AVLGrayWare[Bundler]/Win32.Prepscram
Kingsoftmalware.kb.a.1000
XcitiumApplication.Win32.Prepscram.VF@83qvbm
MicrosoftSoftwareBundler:Win32/Prepscram
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.Prepscram.A
VaristW32/S-218508cc!Eldorado
AhnLab-V3PUP/Win32.StartSurf.R262243
VBA32BScope.Malware-Cryptor.Hlux
ALYacTrojan.GenericKDZ.68104
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B56D (CLASSIC)
YandexTrojan.Kryptik!P1MZ5//ZOJw
IkarusPUA.Win32.Prepscram
MaxSecureTrojan.Malware.73761816.susgen
FortinetW32/GenKryptik.CUPB!tr
AVGWin32:MWrich-A [Trj]
Cybereasonmalicious.e3152b
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.GNOE?

Win32/Kryptik.GNOE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment