Malware

Win32/Kryptik.GZUS malicious file

Malware Removal

The Win32/Kryptik.GZUS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GZUS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com

How to determine Win32/Kryptik.GZUS?


File Info:

crc32: CD907669
md5: 3d594d2530406a230b341ed37807e0b0
name: lastimg.png
sha1: 702d0d53294b61315c1138be967b0072c177656e
sha256: 3c1338bf3319e3e82d824df6f3b3b85f3fb22ac41e27301b121b80fb2e978319
sha512: 548b31168877d69cd1f236de104ae0c0d837ea7fd1e9d0e867151fd253e1e7d6e0e6e4006219837c57f9c047173aa0bf58ace918b51224a89f9eb6208ac741e6
ssdeep: 6144:PtzicfktVEAQ55LINHd3ezBs47zH1iRmQiFIsbp04yUGEcB6++45p7KYG0uuuuu:1zXktKAg2H10BsybWzhip04da+Wp7/G
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GZUS also known as:

MicroWorld-eScanTrojan.Agent.EJNS
FireEyeGeneric.mg.3d594d2530406a23
K7AntiVirusTrojan ( 0055df0b1 )
BitDefenderTrojan.Agent.EJNS
BitDefenderThetaGen:NN.ZexaE.33558.vqW@auHj8eiG
ESET-NOD32a variant of Win32/Kryptik.GZUS
GDataTrojan.Agent.EJNS
KasperskyTrojan-Dropper.Win32.Agent.bjzgwg
Ad-AwareTrojan.Agent.EJNS
EmsisoftTrojan.Agent.EJNS (B)
Trapminesuspicious.low.ml.score
APEXMalicious
WebrootW32.Trojan.Emotet
Endgamemalicious (high confidence)
AhnLab-V3Malware/Win32.Generic.C3813979
ZoneAlarmTrojan-Dropper.Win32.Agent.bjzgwg
MAXmalware (ai score=86)
VBA32BScope.TrojanBanker.Emotet
PandaTrj/TrickBot.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Kryptik.GZUS?

Win32/Kryptik.GZUS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment