Malware

Win32/Kryptik.GVAX (file analysis)

Malware Removal

The Win32/Kryptik.GVAX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GVAX virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GVAX?


File Info:

crc32: 0FF13A9F
md5: 97cbd99bafda2c1207bb930be8c83bf7
name: 97CBD99BAFDA2C1207BB930BE8C83BF7.mlw
sha1: 98f6a64d20ab0ce9d40a56371b8392f4ee42f8c6
sha256: 984ab421576219b21ed4e2cf6ce35fe7a9995cafc6df793a121b11e22a64770a
sha512: f140414159cdb6a467f155e798c19304a15ca943094fe8bb06d6ae0a934aa4a182a3c102bb3263cfdbc62bfdd4931cc1b5c3b719880108614ad36c04fd473f34
ssdeep: 3072:Zl29MaGtI5PoFWhi1sHTkQZYNqlKLXnRp:Zl29MIMGajLXT
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

FileVersion: 2.66
CompanyName: NirSoft
ProductName: NirCmd
ProductVersion: 2.66
FileDescription: NirCmd
OriginalFilename: NirCmd.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GVAX also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f8bc31 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5047
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber
CylanceUnsafe
ZillyaTrojan.CryptXXX.Win32.638
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/CryptXXX.751d01e4
K7GWTrojan ( 004f8bc31 )
Cybereasonmalicious.bafda2
CyrenW32/S-b308e227!Eldorado
SymantecRansom.CryptXXX!g17
ESET-NOD32a variant of Win32/Kryptik.GVAX
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.CryptXXX.asdgxe
BitDefenderGen:Variant.Ransom.CryptXXX.1
NANO-AntivirusTrojan.Win32.Kryptik.fjnrhj
MicroWorld-eScanGen:Variant.Ransom.CryptXXX.1
TencentMalware.Win32.Gencirc.10b589a7
Ad-AwareGen:Variant.Ransom.CryptXXX.1
SophosMal/Generic-S
ComodoMalware@#qx2xcqdwv05n
BitDefenderThetaGen:NN.ZexaF.34686.gy1@a0YXMDjU
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCRYPMIC.SM4
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.97cbd99bafda2c12
EmsisoftGen:Variant.Ransom.CryptXXX.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.CryptXXX.adn
AviraHEUR/AGEN.1128192
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tovicrypt!rfn
AegisLabTrojan.Win32.CryptXXX.4!c
GDataGen:Variant.Ransom.CryptXXX.1
AhnLab-V3Trojan/Win32.CryptXXX.R188042
Acronissuspicious
McAfeeArtemis!97CBD99BAFDA
MAXmalware (ai score=100)
VBA32TrojanRansom.Tovicrypt
MalwarebytesRansom.CryptXXX
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCRYPMIC.SM4
RisingRansom.CryptXXX!8.5DF0 (CLOUD)
YandexTrojan.GenAsa!rPlCHhCY5Gw
IkarusTrojan-Ransom.Tovicrypt
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GVAX?

Win32/Kryptik.GVAX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment