Malware

Win32/Kryptik.GXOM removal guide

Malware Removal

The Win32/Kryptik.GXOM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GXOM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GXOM?


File Info:

crc32: 56E3488E
md5: 209cac3fa3dc700ed82eb0abf31c3a3d
name: 209CAC3FA3DC700ED82EB0ABF31C3A3D.mlw
sha1: 612bbfbb7c2bd60142046abe6381ac3349e06c1a
sha256: 986030c7d281e36317257f9fef2de47ba2cf9ac1c1fce13fd1c19f8198a8c3be
sha512: f9e5cfc8cbcaf1e2cba8be2769530f55fec0d65b5ff204866f398f749a28d099294fdc96e3875e3aa29ad92f4ba4b01d356cee7f7772d32e6e3db41599e1dbb8
ssdeep: 12288:AlqPEDBAKyL8SmadgwtEwRBRLZleVG/it:q6RnZ1/i
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: CALCDRIV
FileVersion: 1.0.001
CompanyName:
LegalTrademarks:
ProductName: CALCDRIV
ProductVersion: 1.0.001
FileDescription: CALCDRIV MFC Application
OriginalFilename: CALCDRIV.EXE
Translation: 0x0409 0x04e4

Win32/Kryptik.GXOM also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader30.29209
MicroWorld-eScanGen:Variant.Zusy.304714
FireEyeGeneric.mg.209cac3fa3dc700e
ALYacGen:Variant.Zusy.304714
SangforMalware
K7AntiVirusTrojan ( 0055b8921 )
BitDefenderGen:Variant.Zusy.304714
K7GWTrojan ( 0055b8921 )
TrendMicroTrojanSpy.Win32.EMOTET.SMB.hp
BitDefenderThetaGen:NN.ZexaF.34634.Py1@aiTzd2ei
CyrenW32/Agent.BHG.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
ClamAVWin.Dropper.Emotet-7351589-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
Ad-AwareGen:Variant.Zusy.304714
SophosMal/EncPk-APC
F-SecureHeuristic.HEUR/AGEN.1119078
InvinceaML/PE-A + Mal/EncPk-APC
McAfee-GW-EditionBehavesLike.Win32.Emotet.jm
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
JiangminTrojan.Banker.Emotet.lsv
AviraHEUR/AGEN.1119078
MicrosoftTrojan:Win32/Emotet.BX!MTB
GridinsoftTrojan.Win32.Agent.dd!n
ArcabitTrojan.Zusy.D4A64A
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataWin32.Trojan-Spy.Emotet.O9U6F0
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R299397
Acronissuspicious
McAfeeTrickbot-FWP!209CAC3FA3DC
MAXmalware (ai score=89)
MalwarebytesTrojan.Emotet
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GXOM
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMB.hp
RisingTrojan.Emotet!1.BE18 (CLASSIC)
YandexTrojan.GenAsa!DNmxbEHWMwQ
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.GXIK!tr
WebrootW32.Trojan.Gen
AVGFileRepMalware
Qihoo-360HEUR/QVM09.0.3A86.Malware.Gen

How to remove Win32/Kryptik.GXOM?

Win32/Kryptik.GXOM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment