Malware

Win32/Kryptik.GXMG malicious file

Malware Removal

The Win32/Kryptik.GXMG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GXMG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • A scripting utility was executed
  • Attempts to stop active services
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GXMG?


File Info:

crc32: 39CFCA13
md5: 81947164b878eb0d93f0d0377719cb4b
name: 81947164B878EB0D93F0D0377719CB4B.mlw
sha1: 7d08061c1a090c1c1c7241c328af93545e6de30f
sha256: 589509e084f251632d9a7099db4f476d93dd1185577b9636b23d37ab256609dc
sha512: 8ab64d90be75d525005021bcd0c6d6df5a7925b5b4bd543799f63d668302fcde0e395c96279d29a853740bb17fea5ba6525da4787b43ca696f39aafd6121d288
ssdeep: 6144:wYRbOlNHro7+XETN6OjHpl+vQDZdQ5glPyIMv8Z7EJxkt6YN:w2OT98wO7pl/TQEaIQwgQIYN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GXMG also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00559fc91 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader30.27560
ClamAVWin.Dropper.Tofsee-7433714-0
CAT-QuickHealRansom.Stop.MP4
McAfeeTrojan-FRKJ!81947164B878
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2012855
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 00559fc91 )
Cybereasonmalicious.4b878e
CyrenW32/Kryptik.ALO.gen!Eldorado
SymantecPacked.Generic.561
ESET-NOD32a variant of Win32/Kryptik.GXMG
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.58629
NANO-AntivirusTrojan.Win32.Zenpak.gehzfg
MicroWorld-eScanTrojan.GenericKDZ.58629
TencentWin32.Trojan-dropper.Agent.Dzjo
Ad-AwareTrojan.GenericKDZ.58629
SophosMal/Generic-S + Mal/GandCrypt-A
ComodoMalware@#2ukkyuabf3s1f
F-SecureHeuristic.HEUR/AGEN.1106357
BitDefenderThetaGen:NN.ZexaF.34236.zC0@aKVFiXbi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.SHADE.THJBEAI
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
FireEyeGeneric.mg.81947164b878eb0d
EmsisoftTrojan.GenericKDZ.58629 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Zenpak.agg
AviraHEUR/AGEN.1106357
Antiy-AVLTrojan/Win32.Zenpak
MicrosoftRansom:Win32/Shade.PA!MTB
ArcabitTrojan.Generic.DE505
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKDZ.58629
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
VBA32Malware-Cryptor.Azorult.gen
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.SHADE.THJBEAI
RisingTrojan.Generic@ML.90 (RDML:SZGVEttpCqj+87U6IC33Hw)
YandexTrojan.Kryptik!pMRIvi4glb8
IkarusTrojan-Ransom.Shade
FortinetW32/CoinMiner.HPDF!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GXMG?

Win32/Kryptik.GXMG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment