Malware

Win32/Kryptik.GFZG (file analysis)

Malware Removal

The Win32/Kryptik.GFZG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GFZG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable Windows Defender

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com

How to determine Win32/Kryptik.GFZG?


File Info:

crc32: 4FE789FD
md5: 992f3f140b1b3a65b92e17d821e60eac
name: 992F3F140B1B3A65B92E17D821E60EAC.mlw
sha1: 807f9dd3b9eaf9bdd9fef174330850fb540c6cc7
sha256: d8d83ec4c3dc16cc7e323ec108cb7848905cb663842175241e765e9d33ce64b6
sha512: 7c335a66c581611d0b08847c9457ae408c193ffb37e6ebc005d8ce8baf5d57bdef43424ddf34d1ffb883538ddca2b4197c6038ccec4ba2cd945fe64cbb7e1f2a
ssdeep: 6144:O4sdA7Qv5/HDQw/NYn6d8yq2oVV0gZb4l5:U6eZHD9dLq2/ob4X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GFZG also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052edb01 )
LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
CylanceUnsafe
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
K7GWTrojan ( 0052edb01 )
Cybereasonmalicious.3b9eaf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GFZG
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.4f2a89ce
NANO-AntivirusTrojan.Win32.Inject.farwxm
ViRobotTrojan.Win32.Z.Trickbot.390144
TencentWin32.Trojan.Generic.Hssl
SophosMal/Generic-R + Troj/Trikbot-BD
ComodoMalware@#126lqcldk8tui
BitDefenderThetaGen:NN.ZexaF.34170.xmW@aOId1Eei
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPTRICKBOT.SMA
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.992f3f140b1b3a65
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.anhr
AviraHEUR/AGEN.1113586
eGambitUnsafe.AI_Score_76%
Antiy-AVLTrojan/Generic.ASMalwS.260E41C
MicrosoftTrojan:Win32/Tiggre!rfn
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AhnLab-V3Malware/Win32.Generic.C2472508
McAfeeArtemis!992F3F140B1B
MAXmalware (ai score=99)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.TrickBot.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_HPTRICKBOT.SMA
RisingTrojan.Kryptik!1.B1CE (CLASSIC)
YandexTrojan.Inject!ac9rVHEAw5A
IkarusTrojan-Banker.TrickBot
FortinetW32/Kryptik.GGAU!tr
Paloaltogeneric.ml

How to remove Win32/Kryptik.GFZG?

Win32/Kryptik.GFZG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment