Malware

Win32/Kryptik.GXMH information

Malware Removal

The Win32/Kryptik.GXMH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GXMH virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GXMH?


File Info:

crc32: 9B7C3584
md5: f267d07c82912e0222666aa2cdc4cbee
name: slot.exe
sha1: 630f7d9cbbb0af1a0d90502bc4be4dbc32b458de
sha256: 5c7f5813142029aa1a1326ebef5b7664ab93e0c6bb40cbb40bf9146556a783f3
sha512: 1ccfb880532191238f8a1da2448b83ba7128868431b65909bbc7ebfc29a87ab6bc1060ac56b736d769edb8d703b655f9d5fb13fd18bbc1257dfaba0a8d8bdc42
ssdeep: 3072:8nkoa1KCPowRKbP7L10uxE232hxeF6HGqZ:ekoaVHa9x32hxq8Go
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GXMH also known as:

MicroWorld-eScanTrojan.GenericKD.32603115
CAT-QuickHealRansom.Stop.MP4
ALYacTrojan.Agent.DelShad
MalwarebytesTrojan.MalPack.GS.Generic
ZillyaTrojan.Kryptik.Win32.1827754
SangforMalware
K7AntiVirusTrojan ( 0055a0261 )
BitDefenderTrojan.GenericKD.32603115
K7GWTrojan ( 0055a0261 )
TrendMicroTROJ_GEN.R015C0DJL19
BitDefenderThetaGen:NN.ZexaF.33550.oC0@auu5ZOpi
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Kryptik.GXMH
TrendMicro-HouseCallTROJ_GEN.R015C0DJL19
Paloaltogeneric.ml
GDataTrojan.GenericKD.32603115
KasperskyTrojan.Win32.DelShad.ble
AlibabaTrojan:Win32/DelShad.745ae159
NANO-AntivirusTrojan.Win32.Kryptik.geemfv
AegisLabTrojan.Win32.Generic.4!c
APEXMalicious
RisingDownloader.Dofoil!8.322 (TFE:6:qFwI1sROWJO)
Ad-AwareTrojan.GenericKD.32603115
SophosMal/Generic-S
ComodoMalware@#20hnqzz5jvg3p
DrWebTrojan.Siggen8.51557
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUPXDP.dt
FireEyeGeneric.mg.f267d07c82912e02
EmsisoftTrojan.GenericKD.32603115 (B)
CyrenW32/Trojan.SEUR-1153
JiangminTrojan.DelShad.jg
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1045033
Antiy-AVLTrojan/Win32.SelfDel
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F17BEB
AhnLab-V3Trojan/Win32.MalPe.R295249
ZoneAlarmTrojan.Win32.DelShad.ble
MicrosoftTrojan:Win32/Pynamer.B!rfn
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=100)
VBA32BScope.Trojan.Chapak
CylanceUnsafe
PandaTrj/GdSda.A
YandexTrojan.DelShad!
IkarusRansom.Win32.Shade
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/GenKryptik.DVUI!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360HEUR/QVM10.2.A7F3.Malware.Gen

How to remove Win32/Kryptik.GXMH?

Win32/Kryptik.GXMH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment