Malware

Win32/Kryptik.GFHK malicious file

Malware Removal

The Win32/Kryptik.GFHK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GFHK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.GFHK?


File Info:

name: F6FB0CD7465AEC1744B1.mlw
path: /opt/CAPEv2/storage/binaries/6bddb28846ac69c46a5edf74ab3a17d7be5f728930708eba6d9bfd6fe89b5e25
crc32: 77221B83
md5: f6fb0cd7465aec1744b12af96b112343
sha1: 1db645e1ad61c6987c47832c6e1d241ce085521a
sha256: 6bddb28846ac69c46a5edf74ab3a17d7be5f728930708eba6d9bfd6fe89b5e25
sha512: f2f482171958ad042e59e604b2b3b91d04533b51cad9ca1b369c8b8bd644ebc0a63d6a2ffbfbc5a5311aaa6a5ea70a4bfda15fd667062fcb0c79e29556bfe0a3
ssdeep: 1536:CecjaOoC4/4TMfIGBMRc2F+U+0Bwi7zmrO7oqkSZZZ3gURD8ib8f:C/LoMTqfiPBwiHmrOSUNRD5bi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149939D42BB15C285F8C68A300427CFF54FA1BDB5EB67C256678E730FE93F042A129A45
sha3_384: f724ee5a63268f51a32c27522637487f99e5333209966651b900214cf82b96f7da43114ed1b416114233d7f510aaf756
ep_bytes: 558bec81ecec010000a1ec0941008985
timestamp: 1970-01-14 05:44:10

Version Info:

Comments:
LegalCopyright: License: MPL 2
CompanyName: Mozilla Foundation
FileDescription:
FileVersion: 51.0.1
ProductVersion: 51.0.1
InternalName:
LegalTrademarks: Mozilla
OriginalFilename: maintenanceservice.exe
ProductName: Firefox
BuildID: 20170125094131
Translation: 0x0000 0x04b0

Win32/Kryptik.GFHK also known as:

Elasticmalicious (high confidence)
SkyhighGenericRXVY-TJ!F6FB0CD7465A
Cylanceunsafe
ZillyaDownloader.Geral.Win32.13407
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GFHK
APEXMalicious
KasperskyVHO:Trojan-PSW.Win32.Fareit.gen
NANO-AntivirusTrojan.Win32.Geral.ezpizc
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11523f00
F-SecureTrojan.TR/AD.Inject.gmp
DrWebTrojan.Chanitor.31
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.f6fb0cd7465aec17
SophosML/PE-A
JiangminTrojanDownloader.Geral.efc
AviraTR/AD.Inject.gmp
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Zbot.SIBD25!MTB
ZoneAlarmVHO:Trojan-PSW.Win32.Fareit.gen
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C2455461
McAfeeGenericRXVY-TJ!F6FB0CD7465A
VBA32BScope.TrojanDownloader.Geral
PandaTrj/GdSda.A
YandexTrojan.DL.Geral!7B2WIFho7bE
SentinelOneStatic AI – Suspicious PE
BitDefenderThetaGen:NN.ZexaF.36804.fq0@aWjW6koi
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Win32/Kryptik.GFHK?

Win32/Kryptik.GFHK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment