Malware

Win32/Kryptik.GVHC removal tips

Malware Removal

The Win32/Kryptik.GVHC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GVHC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Belarusian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Win32/Kryptik.GVHC?


File Info:

crc32: A07D0D0F
md5: c9a9806e8594a4e26c365e4ec2fc83df
name: C9A9806E8594A4E26C365E4EC2FC83DF.mlw
sha1: 30c512e1f6ba2fdabcf098b887bddaeaa6319b44
sha256: b29ca068a8428d7e146e9ef9815e452fb6308e03bf5e879c4f8f440fd17dedc5
sha512: cd5ca991a855859323a6b42ed3e2a3927d473715df247c7307ad5a8c6959cba101698942603eceaf31495be9a0ed566daef508a74c2146aecd226873e4db5092
ssdeep: 6144:ZLDNO7mvu5Naer/BTyL9HSk4pi0NVBoZSzk9VimUP5YR8SvEy7IMU3Fqu46yY:nO7m+sHnkByskHl25YaScy7IxbdyY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, bhchfkh
InternalName: ytoretv.exe
ProductVersion: 1.9.1
Translation: 0x0847 0x03fc

Win32/Kryptik.GVHC also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055502d1 )
LionicHacktool.Win32.Nekto.3!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.28004
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Ransom.Sodinokibi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.744393ab
K7GWTrojan ( 0055502d1 )
Cybereasonmalicious.e8594a
CyrenW32/Agent.BCK.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GVHC
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Generic-9853074-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusExploit.Win32.Nekto.fvazvz
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-S + Mal/GandCrab-H
ComodoTrojWare.Win32.TrojanDownloader.Dofoil.DI@8ec0xt
BitDefenderThetaGen:NN.ZexaF.34236.xC0@aGxhnxlG
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fh
FireEyeGeneric.mg.c9a9806e8594a4e2
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.AntiAV.bpz
AviraTR/AD.SodinoRansom.fwy
eGambitUnsafe.AI_Score_64%
Antiy-AVLTrojan[Exploit]/Win32.Nekto
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Brsecmon.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Brsecmon.1
AhnLab-V3Win-Trojan/MalPe26.Suspicious.X2012
Acronissuspicious
McAfeeArtemis!C9A9806E8594
MAXmalware (ai score=82)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@ML.97 (RDML:ML4PfK2WMAVKnRjpyZlJKA)
IkarusTrojan.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GVOI!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GVHC?

Win32/Kryptik.GVHC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment