Malware

Win32/Kryptik.GUAR removal guide

Malware Removal

The Win32/Kryptik.GUAR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GUAR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Win32/Kryptik.GUAR?


File Info:

crc32: 3D017A6A
md5: 0b31f40a910c8503c6bfd183e03d192c
name: 0B31F40A910C8503C6BFD183E03D192C.mlw
sha1: 6572cf3ac0b0ddca7213c83784964e712eed8427
sha256: c280312fb5a11710c9d6689fc8922b7431236e75bb80b3eac26f85875946ea36
sha512: 627aa16483e08c788e44143bea75f0ac0fd13fcd14e08c1474cf80c4a9821ff8b2643f88c0c6701267e9d5318b9b02c020d65fc644137d856493804831fd55f7
ssdeep: 6144:GOhmaPcJVqEuH0cS+FSY/uilDc/GoHiembOLYPYiDB:GOhmDJVqf0cSo1Lo/GoHiDRYs
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GUAR also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop9.13962
ClamAVWin.Malware.Score-6995873-0
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Brsecmon.1
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.30880
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Scrop.5e427770
K7GWTrojan ( 0055204a1 )
K7AntiVirusTrojan ( 0055204a1 )
CyrenW32/S-d75e9604!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GUAR
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Scrop.vuf
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Scrop.fteqzs
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan-dropper.Scrop.Fhx
Ad-AwareTrojan.Brsecmon.1
SophosML/PE-A + Mal/GandCrab-G
ComodoTrojWare.Win32.Fakecsrss.AV@88nqyj
BitDefenderThetaGen:NN.ZexaF.34170.wuW@aGcp6fbG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.AZORULT.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.0b31f40a910c8503
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Scrop.ze
AviraHEUR/AGEN.1107506
eGambitUnsafe.AI_Score_89%
Antiy-AVLTrojan/Generic.ASMalwS.2BE83EA
MicrosoftRansom:Win32/Sodinokibi.F
ArcabitTrojan.Brsecmon.1
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Brsecmon.1
AhnLab-V3Win-Trojan/MalPe25.Suspicious.X2021
Acronissuspicious
McAfeeSodinokibi!0B31F40A910C
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.AZORULT.SM.hp
RisingRansom.Sodinokibi!1.CA18 (CLASSIC)
YandexTrojan.DR.Scrop!terw0X1lI/U
IkarusTrojan-Ransom.Sodinokibi
MaxSecureTrojan.Malware.74394516.susgen
FortinetW32/GenKryptik.DQHN!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.GUAR?

Win32/Kryptik.GUAR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment