Malware

About “Win32/Kryptik.GXGS” infection

Malware Removal

The Win32/Kryptik.GXGS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GXGS virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
resolver1.opendns.com
myip.opendns.com
mashallah.at

How to determine Win32/Kryptik.GXGS?


File Info:

crc32: 7F93B5D5
md5: 2c058358db86ad7c423ec6e727136724
name: gab.exe
sha1: 5ccc79e45854673276b8a9b87e9e9ff9f5f1fc8c
sha256: 6fbc10987557b19e1b63d43d9c878c4fdb103f07abf67b5a7f95dcd9d1f17af4
sha512: 7eecc5c5efcb49556d8a23fb680de86a4c9e6de3177d29b6bef3ade79b5c7ff05ac9ca457c09503e8df361ca0f990c7e4259c5991c2c85614d15512cdc05c12a
ssdeep: 24576:vLI2rJMsneTthBlj6VuHjPVCO5TDg0/c2Tl5AKc/9sX9ga0:hpeTtHluVuHMOxg00255xcVsN10
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Intarcia Therapeutics All rights reserved.
InternalName: SpellingsInncence
FileVersion: 2.9.82.9
CompanyName: Intarcia Therapeutics
PrivateBuild: 2.9.82.9
LegalTrademarks: Intarcia Therapeutics All rights reserved.
ProductName: SpellingsInncence
Languages: English
ProductVersion: 2.9.82.9
FileDescription: Lcalities Pid Depended Overturned It Data
Translation: 0x0409 0x04b0

Win32/Kryptik.GXGS also known as:

DrWebTrojan.PWS.Banker1.35544
MicroWorld-eScanTrojan.GenericKD.32577118
FireEyeGeneric.mg.2c058358db86ad7c
CAT-QuickHealTrojan.Multi
McAfeeRDN/Generic PWS.yi
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055950a1 )
BitDefenderTrojan.GenericKD.32577118
K7GWTrojan ( 0055950a1 )
TrendMicroPossible_HPGen-38
BitDefenderThetaGen:NN.ZexaF.32519.0u0@amNjw6pi
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.32577118
KasperskyTrojan-Banker.Win32.Gozi.fcu
AlibabaTrojanBanker:Win32/Gozi.6b342b87
NANO-AntivirusTrojan.Win32.Gozi.gczkpe
RisingTrojan.Generic@ML.88 (RDMK:L8/fBmprWhojY4onqFjw/A)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32577118 (B)
ComodoMalware@#356kdlsfknp9j
F-SecureTrojan.TR/AD.Rovnix.pmkbu
ZillyaTrojan.Kryptik.Win32.1783808
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
SophosMal/Generic-S
IkarusTrojan-Spy.Remcos
CyrenW32/Trojan.GSRM-3764
JiangminTrojan.Banker.Gozi.yy
WebrootW32.Trojan.GenKD
AviraTR/AD.Rovnix.pmkbu
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Generic.D1F1165E
ZoneAlarmTrojan-Banker.Win32.Gozi.fcu
MicrosoftTrojan:Win32/Skeeyah.A!rfn
AhnLab-V3Malware/Win32.Possible_hpgen.C3511316
Acronissuspicious
ALYacTrojan.Banker.Gozi
VBA32BScope.TrojanPSW.Stealer
MalwarebytesTrojan.Ursnif
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.GXGS
TrendMicro-HouseCallPossible_HPGen-38
FortinetW32/Kryptik.GVSM!tr
Ad-AwareTrojan.GenericKD.32577118
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.a1a

How to remove Win32/Kryptik.GXGS?

Win32/Kryptik.GXGS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment