Malware

About “Win32/Kryptik.GSUO” infection

Malware Removal

The Win32/Kryptik.GSUO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GSUO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Authenticode signature is invalid

How to determine Win32/Kryptik.GSUO?


File Info:

name: 66C6BC4E4BDEE3D20917.mlw
path: /opt/CAPEv2/storage/binaries/4313366f85f56f2d8614057970e17ebeac61dc15023cd7285a1c1b2ed026dead
crc32: 42945D5C
md5: 66c6bc4e4bdee3d209176fb281e7fda5
sha1: 7eb31b7a5a8abfa4ed1d54161b6efb63e9f468aa
sha256: 4313366f85f56f2d8614057970e17ebeac61dc15023cd7285a1c1b2ed026dead
sha512: 2038b71f4d1ea0e13b11b339cb548b531d3cf3aaae80c12985f382747a475628dc208f7467d564949f63ad887b8551f5bd6047cfcafa2f268fe7eeb3d93ebd47
ssdeep: 12288:s5hnQCxjzQboj5WzJ/5PoUIXehozrTa4hITGFCQRzJioStm3R:g/jzQboj5WV/htFhe5UMb71Stmh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T173E4012035C1C133E12224BAC524CBF14E6EBC71D762AE8B76D57E796E386D1A63530A
sha3_384: 9b2c435f0b9407b4ad5ee769034914d139688064cfe75c600ae819ef15d68f2e466bdedede1ceb21c5358569afe54367
ep_bytes: e81d6c0000e978feffffcccccccccccc
timestamp: 2018-10-06 07:08:37

Version Info:

0: [No Data]

Win32/Kryptik.GSUO also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.66c6bc4e4bdee3d2
McAfeeSodinokibi!66C6BC4E4BDE
CylanceUnsafe
K7AntiVirusTrojan ( 0055858a1 )
AlibabaTrojan:Win32/Ursnif.bd2d0e80
K7GWTrojan ( 0055858a1 )
Cybereasonmalicious.e4bdee
ESET-NOD32a variant of Win32/Kryptik.GSUO
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Kryptik.fqhxrs
MicroWorld-eScanTrojan.Brsecmon.1
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Wqne
Ad-AwareTrojan.Brsecmon.1
EmsisoftTrojan.Brsecmon.1 (B)
F-SecureHeuristic.HEUR/AGEN.1102735
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
SophosMal/Generic-S + Mal/GandCrab-G
SentinelOneStatic AI – Malicious PE
GDataTrojan.Brsecmon.1
JiangminTrojan.Generic.dkewe
eGambitUnsafe.AI_Score_95%
AviraHEUR/AGEN.1102735
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Ursnif
ArcabitTrojan.Brsecmon.1
MicrosoftTrojan:Win32/Ursnif.BS!MTB
AhnLab-V3Win-Trojan/MalPe7.Suspicious.X1951
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.QuW@aeoFSwf
ALYacTrojan.Brsecmon.1
VBA32BScope.Trojan.Fsysna
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
YandexTrojan.Agent!dmgyrQc5fgw
IkarusTrojan.Krypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.HFZD!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.GSUO?

Win32/Kryptik.GSUO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment