Malware

Win32/Kryptik.GBKS removal guide

Malware Removal

The Win32/Kryptik.GBKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GBKS virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine Win32/Kryptik.GBKS?


File Info:

crc32: C11F105E
md5: 785130bf63652d8208bc402d8952e88c
name: 785130BF63652D8208BC402D8952E88C.mlw
sha1: 4901459dfb56d3ad1aac5aa896287a593311429c
sha256: 1a30df10149b4787798b5de25a0d5aa9da00a0db2a1ef2cde1f9f0def830f8d5
sha512: 96e2ac56fa11c0776db8b130a4389fddc7d10d57d316b97d7d570cb2793d10db0d7cc217fc39f2551dc77bbaf91f5a0edfeac621769930c92fb4082975b92827
ssdeep: 24576:zy5JZ3wgyVcmC4E9K/AWMlncE3aPXWc9t1WkEWySt+Pe13vKsq4SJVeI7L:e5JZ+5C79K/IcXPGct4Yype5VhKF7L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GBKS also known as:

K7AntiVirusTrojan ( 005236741 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2634
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacGen:Variant.Adware.ICloader.Symmi.26
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.4809
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Ekstak.e0beb219
K7GWTrojan ( 005236741 )
Cybereasonmalicious.f63652
CyrenW32/S-5737d639!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GBKS
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyTrojan.Win32.Ekstak.daqf
BitDefenderGen:Variant.Adware.ICloader.Symmi.26
NANO-AntivirusTrojan.Win32.InstallCube.ewziwf
MicroWorld-eScanGen:Variant.Adware.ICloader.Symmi.26
TencentMalware.Win32.Gencirc.10c8a6c8
Ad-AwareGen:Variant.Adware.ICloader.Symmi.26
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GEM@7kji8x
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-VJ!785130BF6365
FireEyeGeneric.mg.785130bf63652d82
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.FileTour.diw
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.23F5822
MicrosoftPUADlManager:Win32/InstallCube
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataGen:Variant.Adware.ICloader.Symmi.26
AhnLab-V3PUP/Win32.FileTour.R218140
Acronissuspicious
McAfeePacked-VJ!785130BF6365
MAXmalware (ai score=96)
VBA32Trojan.Ekstak
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!UURjwEn1rNw
IkarusPUA.Win32.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GBKS?

Win32/Kryptik.GBKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment