Malware

Win32/Kryptik.GFFU removal guide

Malware Removal

The Win32/Kryptik.GFFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GFFU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:50000
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
dismissey.com
euphratt.com

How to determine Win32/Kryptik.GFFU?


File Info:

crc32: 1163BB6B
md5: da9bf12dddc87a43b06683bc3783c832
name: DA9BF12DDDC87A43B06683BC3783C832.mlw
sha1: 2a8fd1e83f2a8d8ac9d56b785e44a2d2c3ca5309
sha256: 237a0f2653c57a88c39f2aa1ec8434a52422007e92798beff0fe723d99737c13
sha512: bbb8d6ba29ef00f91424605025161631804cdcc72aca6e43a40f01e7e01dec8647991afd36f06fcfcd00d576dd5d47e58d44740c8b68d0eeb2e0fb6b4b8997f5
ssdeep: 12288:N/PwczLxzQyBboqnFu1Y3ncAzoccdqQdzQMXoMmLf:K2zQyBb3FMl0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2012 Marin Software To. All rights reserved.
InternalName: Card Rock
FileVersion: 7, 4, 8296, 1251
CompanyName: Marin Software To
ProductName: Card Rock
ProductVersion: 7, 4, 8296, 1251
FileDescription: Card Rock
OriginalFilename: Talkevent.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GFFU also known as:

K7AntiVirusTrojan ( 0052d2c91 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.IcedID.6
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zard.53
CylanceUnsafe
ZillyaTrojan.IcedID.Win32.2
SangforPUP.Win32.Strictor.161061
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0052d2c91 )
Cybereasonmalicious.dddc87
CyrenW32/S-2efaecbc!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GFFU
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Zusy-6857557-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.53
NANO-AntivirusTrojan.Win32.IcedID.fackqi
MicroWorld-eScanGen:Heur.Mint.Zard.53
TencentMalware.Win32.Gencirc.10b2b464
Ad-AwareGen:Heur.Mint.Zard.53
SophosMal/Generic-S
ComodoTrojWare.Win32.IcedID.E@7nsb1y
BitDefenderThetaGen:NN.ZexaF.34294.4y0@ae77mJji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericR-MIU!DA9BF12DDDC8
FireEyeGeneric.mg.da9bf12dddc87a43
EmsisoftGen:Heur.Mint.Zard.53 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1106351
Antiy-AVLTrojan/Generic.ASMalwS.2547430
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
GDataGen:Heur.Mint.Zard.53
AhnLab-V3Trojan/Win32.Kryptik.R225806
Acronissuspicious
McAfeeGenericR-MIU!DA9BF12DDDC8
MAXmalware (ai score=99)
VBA32BScope.Trojan.Azden
MalwarebytesTrojan.Injector
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.97 (RDML:xEw8NaGeP47Nc7Pvwc6yFQ)
YandexTrojan.PWS.IcedID!T6/Tm5aJrKE
IkarusTrojan.Crypt
FortinetW32/Generic.AC.412581!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GFFU?

Win32/Kryptik.GFFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment