Malware

Win32/Kryptik.GYRV removal guide

Malware Removal

The Win32/Kryptik.GYRV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GYRV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GYRV?


File Info:

name: 742A0766D6E743F987D8.mlw
path: /opt/CAPEv2/storage/binaries/f379a31d5c9988e53cb2042227eee1e18caed6b61b47bca51d50432fc0445dfd
crc32: 05E2D9F6
md5: 742a0766d6e743f987d8a8cb265f06f7
sha1: 6e0d17024a4c7b7db22759de3ce9bc3b64d9d214
sha256: f379a31d5c9988e53cb2042227eee1e18caed6b61b47bca51d50432fc0445dfd
sha512: f0d89a418b61c4c6805c3fdf3d8068ab2545f1fb23111cea8fb0978fe757a6e3b30cf416e95718321a08130b4e1f041763c49e2c226336fa6c1d34983478de21
ssdeep: 49152:6b9tT1q+iubKXSRLFZJEZ1bw/FlDaO7AvP8WOf3qobVn2VO9oJPg+8QpDhvk67Jn:858+cbNOsvE1/qoh2O9on8Q7NJRepM+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5063306A5D4CA75C52176BCD32FF2E11B1FBCB190D83393B2468D9A6312AE7C7B015A
sha3_384: 0f98d080cdc86320d1a0ab979257eda8851329824e63c53215cb8b540bab3ce1d3b7174d2858c9b099848471ae61f133
ep_bytes: e893360000e979feffff8b4c2404f7c1
timestamp: 2019-02-16 03:48:52

Version Info:

FileVersion: 28.0.1.46
InternalName2: binokebina.exe
Copyright: Xabitozefesaji. Pesamuhawumeb dayihariduca. Pobodiyayuta wicavakepiyepe femotofuv
Translation: 0x0419 0x0548

Win32/Kryptik.GYRV also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BrsecmonE.1
FireEyeGeneric.mg.742a0766d6e743f9
CAT-QuickHealPUA.MultiPMF.S9110398
McAfeeGenericR-RIL!742A0766D6E7
CylanceUnsafe
K7AntiVirusTrojan ( 0055b6a21 )
AlibabaTrojanPSW:Win32/Azorult.03a26610
K7GWTrojan ( 0055b6a21 )
Cybereasonmalicious.6d6e74
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GYRV
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Trojan.CobaltStrike-7458605-0
KasperskyHEUR:Trojan-PSW.Win32.Azorult.pef
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.Bandit.ghodox
Ad-AwareTrojan.BrsecmonE.1
ComodoMalware@#3fvzx8pgkn7ia
DrWebTrojan.Siggen8.57725
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftTrojan.Crypt (A)
Paloaltogeneric.ml
GDataTrojan.BrsecmonE.1
JiangminTrojanDownloader.Bandit.avo
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.fqqc
Antiy-AVLTrojan/Generic.ASMalwS.2CF505F
ArcabitTrojan.BrsecmonE.1
MicrosoftTrojan:Win32/Predator.PVD!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R299024
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.Vx0@aauFPjh
ALYacTrojan.BrsecmonE.1
MAXmalware (ai score=87)
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@ML.94 (RDML:sP+9W0arIk2O5srAAPMWFw)
YandexTrojan.GenAsa!MEi+oKvMy6s
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74695033.susgen
FortinetW32/Kryptik.GYGT!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/Kryptik.GYRV?

Win32/Kryptik.GYRV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment