Malware

About “Win32/GenKryptik.GHKI” infection

Malware Removal

The Win32/GenKryptik.GHKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GHKI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/GenKryptik.GHKI?


File Info:

name: 5662AC16B0B871174FF9.mlw
path: /opt/CAPEv2/storage/binaries/6f083622501ef1e4442c851147451acca629d27c75c3e827f492416f33c4e64e
crc32: 201F13E7
md5: 5662ac16b0b871174ff9c13b73aef0d0
sha1: de75b20bae37a8a5cab69f04d7b179588a5bbf1f
sha256: 6f083622501ef1e4442c851147451acca629d27c75c3e827f492416f33c4e64e
sha512: bb45aace3e4c64a82c4f6493589fc0d35748d9c9e13bc08b7bf011e30a52c2c2fc70bef5a98c812a1e0dbcdd9028c9e059c427ad21a7f073c821fe4616d77bd3
ssdeep: 12288:UTUJtpztd1J6L7ZfsiMaUhc8zkE16pSuke217jZEwQl1:/rpnDcby1612N1Ql1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T192B4122EE3221B25DB8536F3A7B596CDF71CF3B8266396700484294D0066E3D8277D9B
sha3_384: 5194f14e9f769482c5359161fb5f88744c6c6edb6d3787a4161af6628d3abd6d6100c4140b821d759f1495f1b9c33c1e
ep_bytes: b8a0e65d00ffe04281ee0100000081c0
timestamp: 1971-05-16 00:00:00

Version Info:

0: [No Data]

Win32/GenKryptik.GHKI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.PackZ.a!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.103100
FireEyeGeneric.mg.5662ac16b0b87117
SkyhighBehavesLike.Win32.Generic.hm
ALYacTrojan.GenericKDZ.103100
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.330646
SangforDownloader.Win32.Kryptik.V41j
K7AntiVirusTrojan ( 005a0d3e1 )
AlibabaTrojanDownloader:Win32/PackZ.0bf834a6
K7GWTrojan ( 005a0d3e1 )
ArcabitTrojan.Generic.D192BC
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GHKI
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Barys-10002300-0
KasperskyHEUR:Trojan-Downloader.Win32.PackZ.vho
BitDefenderTrojan.GenericKDZ.103100
NANO-AntivirusTrojan.Win32.PackZ.kejbhf
AvastWin32:Evo-gen [Trj]
TencentTrojan-DL.Win32.Packz.ka
EmsisoftTrojan.GenericKDZ.103100 (B)
F-SecureHeuristic.HEUR/AGEN.1369067
DrWebTrojan.DownLoader46.35776
VIPRETrojan.GenericKDZ.103100
TrendMicroTROJ_GEN.R002C0XKS23
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
VaristW32/Kryptik.KUD.gen!Eldorado
AviraHEUR/AGEN.1369067
Antiy-AVLGrayWare/Win32.Injector.ecav
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.PackZ.vho
GDataTrojan.GenericKDZ.103100
GoogleDetected
AhnLab-V3Trojan/Win.Evo-gen.C5396938
McAfeeArtemis!5662AC16B0B8
MAXmalware (ai score=81)
VBA32BScope.TrojanDownloader.PackZ
MalwarebytesTrojan.MalPack.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0XKS23
RisingTrojan.Injector!1.C865 (CLASSIC)
YandexTrojan.Injector!JbV24g/tXsY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GHKI!tr
BitDefenderThetaGen:NN.ZexaF.36608.GmY@aSVIx4j
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/GenKryptik.GHKI?

Win32/GenKryptik.GHKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment