Malware

Win32/Kryptik.GUGR removal tips

Malware Removal

The Win32/Kryptik.GUGR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GUGR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Win32/Kryptik.GUGR?


File Info:

name: AE7DEE6FE05C214D1AF7.mlw
path: /opt/CAPEv2/storage/binaries/41040c547a61aa46fcffba724d0cd860ab7fd693385ddeebdcefd71b106ca0db
crc32: E2F80BDC
md5: ae7dee6fe05c214d1af78702535f62d5
sha1: a3718ee06702e26b07255245d6eb71ca961c6832
sha256: 41040c547a61aa46fcffba724d0cd860ab7fd693385ddeebdcefd71b106ca0db
sha512: 106ed3c983c1dc635608eadfaea81e618c09927b3d11b939740640b6005738b617c85c531d2aec08fd2df667898744c7dea8e85bdf78822d70cd7449da174e91
ssdeep: 12288:ly4fLQJNcOH75kE7wLhklc+jjBllMYhjY7m7AcP3oKAVQpp0Ngl6sksdzcEFmBfy:lZfLQUOH7550L+c+jjB3MsYC7AcPGVQr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17BF40205BBF5C031D07202732264F72256FEBE7156369D9BB7C90E4D9A389C1972AB23
sha3_384: c336f372698cf55d98fd2f72d041a3de2587ffdcac4688dd35e9c5eebbacbc9767f9cbb1899eafedc234d39a6962adcf
ep_bytes: e8a29e0000e939feffff3b0dc8864b00
timestamp: 2018-05-02 12:38:39

Version Info:

0: [No Data]

Win32/Kryptik.GUGR also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SpyBot.840
MicroWorld-eScanTrojan.GenericKDZ.56727
FireEyeGeneric.mg.ae7dee6fe05c214d
CAT-QuickHealRansom.Stop.MP4
McAfeeSodinokibi!AE7DEE6FE05C
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00550f4f1 )
AlibabaTrojanDownloader:Win32/Mufila.fb01a5ef
K7GWTrojan ( 00550f4f1 )
Cybereasonmalicious.fe05c2
BitDefenderThetaGen:NN.ZexaF.34062.VuW@aaMUGHoG
CyrenW32/Zonidel.A.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GUGR
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Dofoil.gen
BitDefenderTrojan.GenericKDZ.56727
NANO-AntivirusTrojan.Win32.Azorult.fsidfb
AvastWin32:Trojan-gen
TencentWin32.Trojan-qqpass.Qqrob.Lpll
Ad-AwareTrojan.GenericKDZ.56727
EmsisoftTrojan.GenericKDZ.56727 (B)
ComodoTrojWare.Win32.Fakecsrss.AV@88nqyj
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.bh
SophosMal/Generic-R + Mal/GandCrab-G
GDataTrojan.GenericKDZ.56727
JiangminTrojanDropper.Scrop.zg
WebrootW32.Adware.Gen
AviraTR/AD.PredatorThief.dco
Antiy-AVLTrojan/Generic.ASMalwS.2BF327B
MicrosoftTrojan:Win32/Mufila.DSK!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MalPe13.Suspicious.X1974
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacTrojan.GenericKDZ.56727
MalwarebytesTrojan.MalPack.GS.Generic
APEXMalicious
RisingTrojan.Generic@ML.88 (RDML:DTI+7MU5bodS0Y/srd5rYQ)
YandexTrojan.PWS.Azorult!7cIfnqacgSE
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.DLJK!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.GUGR?

Win32/Kryptik.GUGR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment