Malware

About “Win32/Kryptik.GUUF” infection

Malware Removal

The Win32/Kryptik.GUUF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GUUF virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Punjabi
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GUUF?


File Info:

crc32: 23AF4243
md5: 321a1dbfa921c5fe6c47e64bcff94c0b
name: 321A1DBFA921C5FE6C47E64BCFF94C0B.mlw
sha1: 4cab748c9b5c42fcb020cb521e844b65e973385a
sha256: c3d4aa7f8143957c6b82885f8d1f292fcdf54001d1928bdafdd3332ba12b2c7a
sha512: 00dec01d6aa6ae6766f6f85cf5e74a0bd7217554593dc9f2e8f3974da9a3c717249ee9b79660685a1979676020430bd4bce4e897ca522485617ea3989ef3dab4
ssdeep: 12288:jK+uC3w4cPBMvFCdGmyf8OsOvoNJmowKjfs/L/v6Av7ErG:jFi4ptIrOTvonmopsL/BgG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GUUF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00555e5a1 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.26585
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Brsecmon.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1682395
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Stealer.c0efdbc0
K7GWTrojan ( 00555e5a1 )
Cybereasonmalicious.fa921c
CyrenW32/Kryptik.ACZ.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GUUF
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.Win32.Stealer.nlu
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Stealer.fttecm
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Generic.Lfzu
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/GandCrab-H
ComodoMalware@#10zkd0bky5fu3
F-SecureHeuristic.HEUR/AGEN.1107506
BitDefenderThetaGen:NN.ZexaF.34236.IyW@am08yqhG
VIPREFraudTool.Win32.MSRemovalTool.ek!a (v)
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
FireEyeGeneric.mg.321a1dbfa921c5fe
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1107506
Antiy-AVLTrojan[Spy]/Win32.Stealer
MicrosoftTrojan:Win32/Occamy.CC3
ArcabitTrojan.Brsecmon.1
ZoneAlarmTrojan-Spy.Win32.Stealer.nlu
GDataTrojan.Brsecmon.1
AhnLab-V3Win-Trojan/MalPe25.Suspicious.X2011
Acronissuspicious
McAfeeTrojan-FRGI!321A1DBFA921
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Kryptik!1.BA76 (CLASSIC)
YandexTrojanSpy.Stealer!n9818nomvNo
IkarusTrojan.Krypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GVOI!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GUUF?

Win32/Kryptik.GUUF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment