Malware

How to remove “Win32/Kryptik.GYSH”?

Malware Removal

The Win32/Kryptik.GYSH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Kryptik.GYSH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Win32/Kryptik.GYSH?


File Info:

crc32: C522202A
md5: f6841caa5e4431ae74bc45c170322076
name: ffddryj2_9861296.exe
sha1: cc72d8e04f25a8c2d144edc53a4f2bcbd076630f
sha256: b08b76582f70f1624f65a5c00a4a633c350351a76cd05b0e8c768dc79b5a2bfe
sha512: 8d90c93ed161b22e4a4407f10a94390c15f2b0cc5161f9683bb4e41f9c6a3693cd01c6cf82eef0835c0a0b03b52bbef84e71a8c2b8d90f2646fa21f40d654af1
ssdeep: 1536:EKa8RxGrBqq8IBn5hf3LP+wzvuxaIqGTuuwvHikkHChLgJ48oiuhNoB8EQVK8FMt:S60CwzvuxaId6thElOeTQM8FMaJp2r
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GYSH also known as:

MicroWorld-eScanTrojan.GenericKD.32741906
FireEyeGeneric.mg.f6841caa5e4431ae
McAfeeEmotet-FOQ!F6841CAA5E44
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32741906
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.32515.hqX@aOU0SXli
F-ProtW32/Emotet.ACD.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
GDataTrojan.GenericKD.32741906
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Emotet!1.BF7A (CLASSIC)
Endgamemalicious (high confidence)
SophosMal/EncPk-APC
F-SecureTrojan.TR/AD.Emotet.ldxvp
DrWebTrojan.Emotet.810
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Crypt
CyrenW32/Emotet.ACD.gen!Eldorado
JiangminTrojan.Banker.Emotet.mme
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.ldxvp
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Casur
MicrosoftTrojan:Win32/Emotet.AU!MTB
ArcabitTrojan.Generic.D1F39A12
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Trojan/Win32.Emotet.R300601
ALYacTrojan.GenericKD.32741906
Ad-AwareTrojan.GenericKD.32741906
MalwarebytesTrojan.Emotet
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GYSH
TrendMicro-HouseCallTROJ_GEN.R011C0DKO19
FortinetW32/GenKryptik.DYHX!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360HEUR/QVM07.1.680B.Malware.Gen

How to remove Win32/Kryptik.GYSH?

Win32/Kryptik.GYSH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment