Malware

Win32/GenKryptik.GHKI malicious file

Malware Removal

The Win32/GenKryptik.GHKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GHKI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/GenKryptik.GHKI?


File Info:

name: FDF4930590967956F983.mlw
path: /opt/CAPEv2/storage/binaries/43eb8cb9f05a805ac739c0fb6c0561504c47cac7cf13c0caed9304e3f03022b4
crc32: 13C4447B
md5: fdf4930590967956f9838a53ec5eb561
sha1: 60e7b5d7210b5fdab7f449a38bc1427cfa4b75d9
sha256: 43eb8cb9f05a805ac739c0fb6c0561504c47cac7cf13c0caed9304e3f03022b4
sha512: 2306be64a3f202471266e518f298bc8cb17430d5c7441c5486b8c66ee8739c4d105f15e341d3a018683937ad280baf7fdd05d18d5f66fea39c346c9b4b4d1112
ssdeep: 12288:tmgl2BZGlu0V5tGTm8UO2ouLtJcLcNhxQ+ExSaqzObquEdYSxr:tCG35tGbU9Lt6gNrFExRjbquEdYSxr
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T157C4022EE35A1772C2DA37B3650ED6C1771EA97515A5E7E0246C803C12A7E20937F2F2
sha3_384: 3dfaf9a91a8276a9770ac6181552a2885e18e4d801e9bc953a9077013af3eabbd1f43b98a73c0f456b8065531731ed75
ep_bytes: bba0e65d00ffe389d181eb537bb55e81
timestamp: 1978-03-20 00:00:00

Version Info:

0: [No Data]

Win32/GenKryptik.GHKI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.PackZ.a!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.70979883
ClamAVWin.Malware.Renos-10003934-0
FireEyeGeneric.mg.fdf4930590967956
SkyhighBehavesLike.Win32.Generic.hm
McAfeeArtemis!FDF493059096
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a0cf41 )
AlibabaTrojanDownloader:Win32/PackZ.ff66e7af
K7GWTrojan ( 005a0cf41 )
ArcabitTrojan.Generic.D43B112B
BitDefenderThetaGen:NN.ZexaF.36608.ImZ@a4cRN1k
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GHKI
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.PackZ.vho
BitDefenderTrojan.GenericKD.70979883
AvastWin32:Evo-gen [Trj]
TencentTrojan-DL.Win32.Packz.ka
EmsisoftTrojan.GenericKD.70979883 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
DrWebTrojan.DownLoader46.41240
VIPRETrojan.GenericKD.70979883
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GoogleDetected
AviraTR/Crypt.ULPM.Gen
Antiy-AVLGrayWare/Win32.Injector.ecav
KingsoftWin32.Trojan-Downloader.PackZ.vho
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/ScarletFlash.A
ViRobotTrojan.Win.Z.Packz.560299.IG
ZoneAlarmHEUR:Trojan-Downloader.Win32.PackZ.vho
GDataWin32.Trojan.PSE.855VXQ
VaristW32/Kryptik.JDZ.gen!Eldorado
AhnLab-V3Trojan/Win.Evo-gen.C5526480
VBA32BScope.TrojanDownloader.PackZ
ALYacTrojan.GenericKD.70979883
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CLP23
RisingTrojan.Kryptik!1.D12D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GHKI!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/GenKryptik.GHKI?

Win32/GenKryptik.GHKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment