Malware

Should I remove “Win32/Kryptik.GUXR”?

Malware Removal

The Win32/Kryptik.GUXR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GUXR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GUXR?


File Info:

crc32: 1C05DB2D
md5: b2d7324a401b0bddb17bfebacd50919a
name: B2D7324A401B0BDDB17BFEBACD50919A.mlw
sha1: ff95c90c8dab7cc35f35dec7ba5ba0389dd7fe64
sha256: e723fd7184f4a77f88142f337e806b5d7fc216127571fd3e8cd2f47f528d4648
sha512: a359c8f1d683e1b19a2c6beae0c782c3ba412ca0f486546b9a24048bde6a2613246946da049f5bf81da78be0a657c1444ae24e2150b3bda9273118f2c156ab98
ssdeep: 3072:mcLXTpcvocFIALdm3vL52HBnXTmy5xEKJ9W8NR04E5RyuAl1SWZj7cpOI7YtE0:FLX1qoEd2v928DHER04E58lNj7cTYW0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GUXR also known as:

BkavHW32.Packed.
K7AntiVirusTrojan ( 0040f4c81 )
DrWebTrojan.Mods.1
MicroWorld-eScanGen:Variant.Ser.Razy.4554
ALYacGen:Variant.Ser.Razy.4554
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.380181
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Gepys.3846e374
K7GWTrojan ( 0040f4c81 )
Cybereasonmalicious.a401b0
TrendMicroTROJ_AGENT_057677.TOMB
CyrenW32/GenTroj.BW.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.GUXR
APEXMalicious
AvastWin32:Kryptik-LUA [Trj]
ClamAVWin.Malware.Ulise-6840317-0
GDataGen:Variant.Ser.Razy.4554
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.4554
NANO-AntivirusTrojan.Win32.MlwGen.cqkyhq
ViRobotTrojan.Win32.Z.Kryptik.213400.C
TencentMalware.Win32.Gencirc.10b3a816
Ad-AwareGen:Variant.Ser.Razy.4554
SophosTroj/Gyepis-C
ComodoTrojWare.Win32.Kryptik.BBSW@4xttk5
F-SecureTrojan.TR/ATRAPS.Gen
BitDefenderThetaGen:NN.ZexaF.34110.nqZ@aqG0Iyh
VIPRETrojan.Win32.Kryptik.bsw (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b2d7324a401b0bdd
EmsisoftGen:Variant.Ser.Razy.4554 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/GenTroj.BW.gen!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Trojan.Genkdz
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Unknown
MicrosoftTrojan:Win32/Gepys.PVR!MTB
JiangminTrojan/Generic.awsky
ArcabitTrojan.Ser.Razy.D11CA
AegisLabTrojan.Win32.Generic.lUUy
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Dropper/Win32.Agent.R67796
Acronissuspicious
McAfeeDropper-FFQ!B2D7324A401B
MAXmalware (ai score=85)
VBA32Trojan.AET.24507
MalwarebytesTrojan.ShipUp
PandaTrj/Dtcontx.E
TrendMicro-HouseCallTROJ_AGENT_057677.TOMB
RisingDropper.Gepys!8.15D (TFE:dGZlOgJNtL2csGGXzQ)
YandexTrojan.ShipUp!O6F2dmnve+o
IkarusTrojan-Dropper.Win32.Gepys
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gepys.AA!tr
AVGWin32:Kryptik-LUA [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.d14

How to remove Win32/Kryptik.GUXR?

Win32/Kryptik.GUXR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment