Malware

Win32/Kryptik.GXVG information

Malware Removal

The Win32/Kryptik.GXVG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GXVG virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

statistseobd.xyz

How to determine Win32/Kryptik.GXVG?


File Info:

crc32: D0455F96
md5: b478cb1837411d5b77fd31073e9771dd
name: flashplayer32pp.exe
sha1: 4ad664b8b04669f4a369def5ca1aeb20dd4e2b30
sha256: 28f37f6e43149d4dbd58a785876e9da7bb2025c0c45b2ecdecc9f41478f56171
sha512: c00baf60e02c9d1af84e77def3ee152d61a74217acfcd5e3b2c3eb271dc4b697c7f70c03375afac4ff7ccce37c1f907411d238dc7004c8544a86e0a7a65cf0ae
ssdeep: 3072:hA8R0skf3ZkO+m9orpPrZOkRoNC+cUnBNxmxZJxWxlvxGh9VwQz5NBlblgwslrn:hNgMNrpTjRoNCmQJQDYhrznUxVtt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalNameNew: hsrjdytj.exe
ProductVersion: 2.0.6.4
Translation: 0x0409 0x04e4

Win32/Kryptik.GXVG also known as:

MicroWorld-eScanTrojan.Brsecmon.1
CAT-QuickHealTrojan.Zenpak
McAfeeRDN/Generic.grp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055aae41 )
BitDefenderTrojan.Brsecmon.1
K7GWTrojan ( 0055aae41 )
Cybereasonmalicious.8b0466
Invinceaheuristic
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.Chapak-7370448-0
GDataTrojan.Brsecmon.1
KasperskyTrojan.Win32.Zenpak.nyl
AlibabaBackdoor:Win32/CryptInject.33384966
NANO-AntivirusTrojan.Win32.Zenpak.gfnbze
Paloaltogeneric.ml
AegisLabTrojan.Win32.Zenpak.4!c
TencentWin32.Trojan.Zenpak.Pepk
Ad-AwareTrojan.Brsecmon.1
EmsisoftTrojan.Brsecmon.1 (B)
F-SecureTrojan.TR/Crypt.Agent.xelxj
DrWebTrojan.Encoder.858
ZillyaTrojan.Zenpak.Win32.1346
TrendMicroTrojan.Win32.SMOKELOAD.SMD2.hp
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.fh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b478cb1837411d5b
SophosMal/GandCrab-G
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.JTZI-7554
JiangminTrojanDownloader.Bandit.ath
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.xelxj
Endgamemalicious (high confidence)
ArcabitTrojan.Brsecmon.1
ZoneAlarmTrojan.Win32.Zenpak.nyl
MicrosoftTrojan:Win32/CryptInject.VDS!MTB
AhnLab-V3Trojan/Win32.MalPe.R296857
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34084.uy0@aqUsVVm
ALYacTrojan.Brsecmon.1
MAXmalware (ai score=100)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack.GS.Generic
ESET-NOD32a variant of Win32/Kryptik.GXVG
TrendMicro-HouseCallTrojan.Win32.SMOKELOAD.SMD2.hp
RisingTrojan.Wacatac!8.10C01 (CLOUD)
YandexTrojan.Zenpak!
IkarusTrojan-Ransom.Stop
FortinetW32/Encoder.858!tr
MaxSecureTrojan.Malware.74666850.susgen
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.094

How to remove Win32/Kryptik.GXVG?

Win32/Kryptik.GXVG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment