Malware

Should I remove “Win32/GenKryptik.GHKI”?

Malware Removal

The Win32/GenKryptik.GHKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.GHKI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Win32/GenKryptik.GHKI?


File Info:

name: B4D9292FC9188D0EC3F2.mlw
path: /opt/CAPEv2/storage/binaries/af49f8d5c7a19ac8971051f06fa0b81e14dadefcee92749e173ac30afc2c58d3
crc32: C9656306
md5: b4d9292fc9188d0ec3f23c1384eaacee
sha1: e0683c1be842e01f1e49ec2541ba984d00f44848
sha256: af49f8d5c7a19ac8971051f06fa0b81e14dadefcee92749e173ac30afc2c58d3
sha512: 9bbf59783a7dd300ed8e583777d73ba7eee51b1a12184a3593511f653d31d0eba64c4376a09c860aa91e717eefa8825b394bcf896815327ce9ca5dc6b33a2099
ssdeep: 12288:ZNWAZTmW5zFi82B34udcGoPrEc686SGBOBvy13myjVcB9S:ZNWaTmW5Bi8IcGars86Suiy1NjyB9S
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DFB412A3968B73B0C74170313E9AD8EAA32EEA55136A515214B6214F01BBF7E45F37F0
sha3_384: 3ec11b8b8ade73416f7278847178be720fb16060b16546a795852d943cd6a2b1a40dd2cc79a9a4d64f23836fed4e0e1c
ep_bytes: bea0e65d00ffe621d281c2e2af813781
timestamp: 1975-06-24 00:00:00

Version Info:

0: [No Data]

Win32/GenKryptik.GHKI also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
FireEyeGeneric.mg.b4d9292fc9188d0e
SkyhighBehavesLike.Win32.Generic.hm
Cylanceunsafe
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GHKI
APEXMalicious
ClamAVWin.Packed.Lazy-10001745-0
KasperskyHEUR:Trojan-Downloader.Win32.PackZ.vho
RisingTrojan.Injector!1.E280 (CLASSIC)
F-SecureTrojan.TR/Crypt.ULPM.Gen
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Crypt.ULPM.Gen
VaristW32/Kryptik.JDZ.gen!Eldorado
Antiy-AVLGrayWare/Win32.Injector.ecav
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ZoneAlarmHEUR:Trojan-Downloader.Win32.PackZ.vho
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5394251
BitDefenderThetaGen:NN.ZexaF.36792.GmY@aaWQ4Cm
DeepInstinctMALICIOUS
VBA32BScope.TrojanDownloader.PackZ
MalwarebytesTrojan.MalPack.Generic
PandaTrj/Genetic.gen
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GHKI!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/GenKryptik.GHKI?

Win32/GenKryptik.GHKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment