Malware

Win32/Kryptik.LOW removal instruction

Malware Removal

The Win32/Kryptik.LOW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.LOW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/Kryptik.LOW?


File Info:

name: 455242F8DED88E73A819.mlw
path: /opt/CAPEv2/storage/binaries/db772797cf316f1d3a6c74499cfb5df5fd40106165b6b3b77d9262f0745d46a0
crc32: A9B1D2A0
md5: 455242f8ded88e73a819fe24bf301b14
sha1: e2e4154df83e2ff8e9673fdee2ff82d68495da89
sha256: db772797cf316f1d3a6c74499cfb5df5fd40106165b6b3b77d9262f0745d46a0
sha512: f004e56cc0953772372ff65a0d788a9403b2348f758d258414ce52d5537260c60d11c27de895314a1e876bac63693e41cdbed3bf76e4b8961c98da5c461204de
ssdeep: 6144:r9VnRtUB4b5F3hGOBN66yaFieMvqC+GCczG+SEL5b1b2aHft2nQRSv3rf8XscrF0:bUB4bhxB/HMvxzG+j1bVHFNcf8XziM12
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170942306F9C4F270C6D028F7C24D457A2522AD0E6DA19AAB5F24BF10AF7AC53D16217F
sha3_384: 0f40eac67b9b74d1b48b96974d5c21da3a6f60f8ff84644d07d08553ec0bc54d15a8d3f5487bc1153935da5bdbd8979a
ep_bytes: 60be007047008dbe00a0f8ffc7871070
timestamp: 2008-03-24 01:42:08

Version Info:

0: [No Data]

Win32/Kryptik.LOW also known as:

LionicTrojan.Win32.Gimemo.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.821
MicroWorld-eScanGen:Heur.VIZ.!e!.1
FireEyeGeneric.mg.455242f8ded88e73
ALYacGen:Heur.VIZ.!e!.1
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.3650
SangforRansom.Win32.Gimemo.za
K7AntiVirusTrojan ( 0055dd191 )
AlibabaRansom:Win32/Gimemo.2ed7b787
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.8ded88
BitDefenderThetaGen:NN.ZexaF.34212.AmHfaGzQbUdc
VirITTrojan.Win32.Winlock.BFP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LOW
ClamAVWin.Trojan.Gimemo-585
KasperskyTrojan-Ransom.Win32.Gimemo.za
BitDefenderGen:Heur.VIZ.!e!.1
NANO-AntivirusTrojan.Win32.Gimemo.ihzve
AvastFileRepMalware
TencentWin32.Trojan.Gimemo.Pbpa
Ad-AwareGen:Heur.VIZ.!e!.1
EmsisoftGen:Heur.VIZ.!e!.1 (B)
ComodoMalware@#2uk44mlhvy1nz
VIPREPacked.Win32.PWSZbot.gen (v)
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VIZ.!e!.1
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.185E301
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.A.Gimemo.436864[UPX]
ZoneAlarmTrojan-Ransom.Win32.Gimemo.za
MicrosoftRansom:Win32/LockScreen.AO
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FraudPack.R3415
McAfeeArtemis!455242F8DED8
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingRansom.Gimemo!8.306 (RDMK:cmRtazpoWhXqEZt5dJntBB67pKcV)
YandexTrojan.Gimemo!au7xJMNy31A
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.1899679.susgen
AVGFileRepMalware
PandaGeneric Malware

How to remove Win32/Kryptik.LOW?

Win32/Kryptik.LOW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment