Malware

Win32/Kryptik.GXLG information

Malware Removal

The Win32/Kryptik.GXLG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GXLG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Collects information about installed applications
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GXLG?


File Info:

crc32: F86481A8
md5: fdb49ba0f1f4e6ad835948a901add324
name: FDB49BA0F1F4E6AD835948A901ADD324.mlw
sha1: c81988f105cc8cda9f6858f6e0096eb5cc4714ca
sha256: 8a968c599fa2a769099584124823a51395aac95d4353d1031aaf20a243fb90ea
sha512: c80a04314f91c09ebe7c5c70e329f962beae49474fe122798ffece4e7d0c30871399090dec2dead37284903109ad508b7a18519dd97fb08448c0ab2358025445
ssdeep: 24576:qeEqI3FVXjtzcT4Rn9xIO1Xdmd1oGW6h:GXVpb111NmA6h
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GXLG also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Brsecmon.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.0f1f4e
CyrenW32/Kryptik.AML.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GXLG
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Generic-7338654-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
MicroWorld-eScanTrojan.Brsecmon.1
Ad-AwareTrojan.Brsecmon.1
SophosML/PE-A + Mal/GandCrab-G
ComodoMalware@#8j6frx99yle2
BitDefenderThetaGen:NN.ZexaF.34170.@G0@a0Z4Vipi
TrendMicroTrojan.Win32.SMOKELOAD.SMC2.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FireEyeGeneric.mg.fdb49ba0f1f4e6ad
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.PredatorThief.ahqy
MicrosoftRansom:Win32/Shade.PA!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.Kryptik.R295148
Acronissuspicious
McAfeeTrojan-FRKJ!FDB49BA0F1F4
MAXmalware (ai score=89)
VBA32TrojanDownloader.Bandit
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SMOKELOAD.SMC2.hp
RisingTrojan.Generic@ML.97 (RDMK:ZE5C0gqRWBqgZKSbRuMNag)
YandexTrojan.GenAsa!kYTrsPVioNI
IkarusTrojan-Ransom.Shade
FortinetW32/Kryptik.GXMF!tr
AVGWin32:PWSX-gen [Trj]

How to remove Win32/Kryptik.GXLG?

Win32/Kryptik.GXLG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment