Malware

How to remove “Win32/Kryptik.GZIJ”?

Malware Removal

The Win32/Kryptik.GZIJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GZIJ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

spacestat7.xyz
sxrmailserv19fd.xyz

How to determine Win32/Kryptik.GZIJ?


File Info:

crc32: 63E226C7
md5: 5b65e377513b67d33a3f701be4cf758f
name: ztx777.exe
sha1: a367c4b877954c70a309cc8ce357dc65ae8257db
sha256: d88fdd7365a03ae919b3ee37d7857917937586ceadcd7962fd4f744ced87c845
sha512: 5a4ee7d374f750e896dec3cb0324a2fbd02386b315039dcfe1a56e58593873a345fbee66bd7569d86c661007b6a7ab242849a6ba68e80a2c9b2cb5ba9223b9e2
ssdeep: 6144:9SrNaxeWH0ZjZXIBL3oIxcahgTubi4FUDV9Op:gML0ZjlIBsIej4FUDV92
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9Social Finance. All rights reserved.
InternalName: Asr Attacked
FileVersion: 7.8.97.6
CompanyName: Social Finance
PrivateBuild: 7.8.97.6
LegalTrademarks: Copyright xa9Social Finance. All rights reserved.
Comments: Null Intensifies Linqs Splash
ProductName: Asr Attacked
Languages: English
ProductVersion: 7.8.97.6
FileDescription: Null Intensifies Linqs Splash
OriginalFilename: Asr Attacked
Translation: 0x0409 0x04b0

Win32/Kryptik.GZIJ also known as:

MicroWorld-eScanTrojan.Autoruns.GenericKD.42104279
FireEyeTrojan.Autoruns.GenericKD.42104279
McAfeeRDN/Generic.hbg
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0055d32d1 )
BitDefenderTrojan.Autoruns.GenericKD.42104279
K7GWTrojan ( 0055d32d1 )
TrendMicroTrojan.Win32.WACATAC.USXVPLB19
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.Autoruns.GenericKD.42104279
KasperskyTrojan.Win32.Agent.xacvcu
RisingTrojan.Generic@ML.81 (RDML:RWrHvtByMQIKGzJ8rYM6JA)
Ad-AwareTrojan.Autoruns.GenericKD.42104279
SophosMal/Generic-S
DrWebTrojan.PWS.Siggen2.40479
ZillyaTrojan.Kryptik.Win32.1877104
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Autoruns.GenericKD.42104279 (B)
IkarusTrojan.Win32.Crypt
WebrootW32.Malware.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Occamy
Endgamemalicious (moderate confidence)
ArcabitTrojan.Autoruns.Generic.D28275D7
ZoneAlarmTrojan.Win32.Agent.xacvcu
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C3640446
Acronissuspicious
BitDefenderThetaGen:NN.ZexaE.33550.nmKfaib5JKai
ALYacTrojan.Agent.Wacatac
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.SystemBC
ESET-NOD32a variant of Win32/Kryptik.GZIJ
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPLB19
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Kryptik.GVSM!tr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM11.1.CA47.Malware.Gen

How to remove Win32/Kryptik.GZIJ?

Win32/Kryptik.GZIJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment