Malware

Win32/Kryptik.GNYA removal tips

Malware Removal

The Win32/Kryptik.GNYA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GNYA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system

Related domains:

hashnestsoins.org
survey-smiles.com
ww1.survey-smiles.com

How to determine Win32/Kryptik.GNYA?


File Info:

crc32: 38D138CF
md5: 31e5e241ae9608c2dab0427697be8936
name: 31E5E241AE9608C2DAB0427697BE8936.mlw
sha1: 31e2737eca84b32240677745e13a2998f807532d
sha256: acb5001a3142b37795b9575b70db077aeb07372050dbfa0451079005b5bd0aa1
sha512: 3023c6d878c8d50c57eb033d9a4af16dbf1786a40f4b0ea6132eed4efa2d87c2db707fa9799f267ffaa521d4aee5a767d3ee675a20c51d7c6a362cec6a7d5559
ssdeep: 3072:X0dyniJ3HQsyrLJJigts6Bw2oFMcpt7IrY7iLmhZvte+BWjbpu/lKE27By6P6Ro:kQyHHyrLVBncl2sv8owQIllytSGe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, fikujasuta
InternalName: fabigawo.exe
FileVersion: 7.9.9.51
ProductVersion: 7.9.9.51
Translation: 0x0378 0x04b0

Win32/Kryptik.GNYA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00543fff1 )
LionicTrojan.Win32.Azorult.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24943
CynetMalicious (score: 100)
ALYacTrojan.BrsecmonE.1
CylanceUnsafe
ZillyaTrojan.Azorult.Win32.137
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:Win32/Azorult.bb9e3231
K7GWTrojan ( 00543fff1 )
Cybereasonmalicious.1ae960
CyrenW32/Kryptik.OG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GNYA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-PSW.Win32.Azorult.cch
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.Stealer.fljxdo
MicroWorld-eScanTrojan.BrsecmonE.1
TencentWin32.Trojan-qqpass.Qqrob.Lknt
Ad-AwareTrojan.BrsecmonE.1
SophosMal/Generic-R + Mal/Kryptik-DG
ComodoMalware@#wsphai3uim5z
BitDefenderThetaGen:NN.ZexaF.34236.pu0@aajqIPgi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
FireEyeGeneric.mg.31e5e241ae9608c2
EmsisoftTrojan.BrsecmonE.1 (B)
JiangminTrojanSpy.Stealer.aai
AviraHEUR/AGEN.1107202
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.29EDBC5
MicrosoftTrojan:Win32/Occamy.CAC
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataTrojan.BrsecmonE.1
AhnLab-V3Malware/Win32.Generic.C2899959
McAfeeTrojan-FQPW!31E5E241AE96
MAXmalware (ai score=100)
VBA32BScope.Trojan.Fuery
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@ML.100 (RDMK:Ca57uFvSXbzWQC/iCwQ/Kg)
YandexTrojan.GenAsa!eek6tcosDNg
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GOTY!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GNYA?

Win32/Kryptik.GNYA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment