Malware

Win32/Kryptik.GSKY information

Malware Removal

The Win32/Kryptik.GSKY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GSKY virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • A process attempted to delay the analysis task by a long amount of time.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.ask.com
testcmdz1.tinyupdates.ru
testcmdz2.tinyupdates.ru
testcmdz3.tinyupdates.ru
testcmdz4.tinyupdates.ru
testcmdz5.tinyupdates.ru
testcmdz6.tinyupdates.ru
testcmdz7.tinyupdates.ru
testcmdz8.tinyupdates.ru
testcmdz9.tinyupdates.ru
testcmdz10.tinyupdates.ru
testcmdz11.tinyupdates.ru
testcmdz12.tinyupdates.ru
testcmdz13.tinyupdates.ru
testcmdz14.tinyupdates.ru
testcmdz15.tinyupdates.ru
testcmdz16.tinyupdates.ru
testcmdz17.tinyupdates.ru
testcmdz18.tinyupdates.ru
testcmdz19.tinyupdates.ru
control.tinyupdates.ru
mx-aol.mail.gm0.yahoodns.net

How to determine Win32/Kryptik.GSKY?


File Info:

crc32: 526E7141
md5: bdd455b064413ee7e1997bd10daa4904
name: BDD455B064413EE7E1997BD10DAA4904.mlw
sha1: 37ba78e7278bf63b94c23375d2a8e734797a25f4
sha256: 33677846134841aa2541b5707102646aeedb1fc32a717a58e89a6ff69f0ef7bb
sha512: c9e9f17c88db0364e851ee2bcdea5561a9cfa8156eb240047d8ef0516b8e33ef80429ef2f6c9601fa6a86ed2c1e8cd03ea079d63a599bbe7ab9bb9fe5a6059ee
ssdeep: 6144:jRhn4plaIGmfaQ39Wtn7HGcyKfoPfzrz5lxiz8N7jJ:jalaIGmiQ39KnKc9I5awL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GSKY also known as:

BkavW32.FamVT.CazakoN.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36155453
CAT-QuickHealTrojan.Khalesi
Qihoo-360Win32/Trojan.Khalesi.A
McAfeePacked-XB!BDD455B06441
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Khalesi.4!c
SangforMalware
K7AntiVirusTrojan ( 0052b1cd1 )
BitDefenderTrojan.GenericKD.36155453
K7GWTrojan ( 0052b1cd1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Ulise.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-6947762-1
KasperskyHEUR:Trojan.Win32.Khalesi.gen
AlibabaTrojan:Win32/Khalesi.12e
NANO-AntivirusTrojan.Win32.Khalesi.fmzlvt
ViRobotTrojan.Win32.Khalesi.267776
RisingTrojan.Injector!1.BABB (CLASSIC)
Ad-AwareTrojan.GenericKD.36155453
EmsisoftTrojan.Agent (A)
ComodoTrojWare.Win32.Khalesi.DS@7h11qn
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen7.49534
ZillyaTrojan.Kryptik.Win32.2753857
TrendMicroTrojan.Win32.MALREP.THAAHBA
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.bdd455b064413ee7
SophosMal/Generic-S
IkarusTrojan.Win32.CryptInject
JiangminTrojan.Lethic.aa
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:Win32/CeeInject.ANO!bit
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D227B03D
ZoneAlarmHEUR:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.Khalesi.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.R221226
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34780.zqW@aWkzAuhO
ALYacTrojan.GenericKD.36155453
VBA32BScope.Trojan.Packed
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/GdSda.A
ZonerTrojan.Win32.75824
ESET-NOD32a variant of Win32/Kryptik.GSKY
TrendMicro-HouseCallTrojan.Win32.MALREP.THAAHBA
TencentTrojan.Win32.Khalesi.a
YandexTrojan.GenAsa!mnlcc7nD9jE
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Khalesi.XB!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.064413
Paloaltogeneric.ml
MaxSecureTrojan.Malware.11913586.susgen

How to remove Win32/Kryptik.GSKY?

Win32/Kryptik.GSKY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment