Malware

Win32/GenKryptik.CKKI removal tips

Malware Removal

The Win32/GenKryptik.CKKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.CKKI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

mimino.gdn
tenar.gdn
minor.gdn
tochka.gdn
mostik.gdn
damba.gdn
mastak.gdn

How to determine Win32/GenKryptik.CKKI?


File Info:

crc32: 57B89F68
md5: 1bd39d4b709dc1bd5e8df6db17aa271a
name: 1BD39D4B709DC1BD5E8DF6DB17AA271A.mlw
sha1: 26686642c1e18582d1327ea3ad634b0e8db4c151
sha256: 5f9d0ef3fd6f5579c37d7b797b8049a4732d2b00f0df6e8976e3e19250f13ac5
sha512: f6d3fed90784b89ab38c8ea5491af85f73bd94ae669a9b50849ad9e0fbc809e45d572695c38715dc6419d1b24ecba4cf0404b9f26b8f0494d058f512b2a15f5b
ssdeep: 6144:M8G1PUuJpocevdJ1tcwE3Mlb/nCca7X4K:puJpoBvpOMDCTX4K
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9. All rights reserved. Win Interactive
InternalName: WriterInvesting
FileVersion: 5.5.7.4
CompanyName: Win Interactive
PrivateBuild: 5.5.7.4
LegalTrademarks: xa9. All rights reserved. Win Interactive
Comments: Donaldson Ws Achievement
ProductName: WriterInvesting
Languages: English
ProductVersion: 5.5.7.4
FileDescription: Donaldson Ws Achievement
OriginalFilename: WriterInvesting.exe
Translation: 0x0409 0x04b0

Win32/GenKryptik.CKKI also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Scarab.43
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.130844
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Yakes.f02fbb56
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b709dc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.CKKI
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Yakes.wvsx
BitDefenderGen:Variant.Ransom.Scarab.43
NANO-AntivirusTrojan.Win32.Yakes.fimfff
MicroWorld-eScanGen:Variant.Ransom.Scarab.43
TencentWin32.Trojan.Yakes.Ecbb
Ad-AwareGen:Variant.Ransom.Scarab.43
SophosMal/Generic-S
ComodoMalware@#324xl3ua36v0o
TrendMicroMal_MiliCry-1c
FireEyeGeneric.mg.1bd39d4b709dc1bd
EmsisoftGen:Variant.Ransom.Scarab.43 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Yakes.aakr
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1126114
Antiy-AVLTrojan/Generic.ASMalwS.2718727
MicrosoftTrojan:Win32/Occamy.C5F
GDataGen:Variant.Ransom.Scarab.43
AhnLab-V3Malware/Win32.Milicry.C2635944
Acronissuspicious
McAfeeArtemis!1BD39D4B709D
MAXmalware (ai score=81)
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_MiliCry-1c
YandexTrojan.Yakes!Dd6n5pYzrmA
IkarusTrojan-Ransom.GandCrab
FortinetW32/Generik.OEUNGB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/GenKryptik.CKKI?

Win32/GenKryptik.CKKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment