Malware

Win32/Kryptik.GREI information

Malware Removal

The Win32/Kryptik.GREI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GREI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Kyrgyz
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GREI?


File Info:

crc32: C471AFEE
md5: d1a3c84aa9aca15542d2da13b47f9dd4
name: D1A3C84AA9ACA15542D2DA13B47F9DD4.mlw
sha1: 3fd23408dfc96fc3cfce87c37ff3f4a72d8780a5
sha256: 25296ff722a6e8251f58c9007596cb55ece1b62bf191219a526ff15b17828ce3
sha512: 286d01d0d7de2f52bb11106ed3c0d3670b3cf2d1bb5d84d44ed48662973e784807eedb85ec6b9eca8a1399af5c9694a1ab852c6dd93a836af344822a891dbbf9
ssdeep: 3072:fng3MD3O1q4CV2QJssLFffLD0boEDp/6JJNrURcreANyxqzC:foMK1N1sRfP0cEtELU6VAxp
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Kryptik.GREI also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Phorpiex.1342
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Titirez.hmGfQuEjj@aK
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1945892
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
ESET-NOD32a variant of Win32/Kryptik.GREI
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Titirez.hmGfQuEjj@aK
NANO-AntivirusTrojan.Win32.Scar.fohumi
ViRobotTrojan.Win32.GandCrab.Gen.B
MicroWorld-eScanGen:Heur.Mint.Titirez.hmGfQuEjj@aK
Ad-AwareGen:Heur.Mint.Titirez.hmGfQuEjj@aK
SophosML/PE-A + Mal/GandCrab-G
ComodoTrojWare.Win32.Ransom.GandCrab.PF@890pnk
BitDefenderThetaAI:Packer.5556F6E71F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.RansomGandCrab.cc
FireEyeGeneric.mg.d1a3c84aa9aca155
EmsisoftTrojan-Downloader.Dofoil (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.dgfnr
AviraHEUR/AGEN.1138861
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Script/Phonzy.A!ml
GridinsoftRansom.Win32.Fuerboos.vb!s2
ArcabitTrojan.Mint.Titirez.E2F961
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Mint.Titirez.hmGfQuEjj@aK
AhnLab-V3Trojan/Win32.Fuerboos.C3115278
McAfeeGenericRXAA-AA!D1A3C84AA9AC
MAXmalware (ai score=88)
VBA32BScope.TrojanPSW.Azorult
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgUK+bXsC/PF0A)
YandexTrojan.GenAsa!QYl07pql2hg
IkarusTrojan.Win32.CryptInject
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.HGHW!tr
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM11.1.F5E0.Malware.Gen

How to remove Win32/Kryptik.GREI?

Win32/Kryptik.GREI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment