Malware

Win32/Kryptik.GHFZ removal instruction

Malware Removal

The Win32/Kryptik.GHFZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GHFZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GHFZ?


File Info:

crc32: 78FDBDAA
md5: 480b5c4528d515c14f7eb05b9a81dd07
name: 480B5C4528D515C14F7EB05B9A81DD07.mlw
sha1: 73224c0e442b454f3b44d0c0871232e27475711a
sha256: 0b0f9fd1433a4224fe60e5beb7c45ce128baea6746273cad2bdfa7b954e8768e
sha512: e513a82155baccb28096fbd6e13b7771988dacea5992d4d0c1b8a479334da24d185ac2e79ab6af73c55964373bf2d44c78e36172a9a2ed4ab2e99f8cb8994ded
ssdeep: 3072:Fdan+srMTpBwV5HYmrrUdIQs2gR2cS7lodlPjMdVCXDEKK:i+VkyrsjR2wQnMY3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GHFZ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacGen:Variant.Zusy.287607
CylanceUnsafe
ZillyaBackdoor.Sinowal.Win32.21720
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/GandCrypt.fcbde5e7
K7GWTrojan ( 005331631 )
K7AntiVirusTrojan ( 005331631 )
CyrenW32/S-79ffeeec!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GHFZ
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Gandcrab-6787437-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.287607
NANO-AntivirusTrojan.Win32.Sinowal.fdlmle
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Variant.Zusy.287607
TencentWin32.Trojan.Generic.Pavr
Ad-AwareGen:Variant.Zusy.287607
SophosML/PE-A + Mal/Kryptik-CB
BitDefenderThetaGen:NN.ZexaF.34678.iyW@aqVVSUki
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_HPGen-37b
FireEyeGeneric.mg.480b5c4528d515c1
EmsisoftGen:Variant.Zusy.287607 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GandCrypt.dz
AviraHEUR/AGEN.1103340
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/GandCrypt.DSK!MTB
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Zusy.287607
AhnLab-V3Win-Trojan/Gandcrab02.Exp
Acronissuspicious
McAfeeTrojan-FPPS!480B5C4528D5
MAXmalware (ai score=95)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.3930054941
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_HPGen-37b
RisingTrojan.Kryptik!1.B2AC (CLOUD)
IkarusTrojan.Crypt
MaxSecureRansomeware.GandCrypt.JZ
FortinetW32/GenKryptik.CNAR!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCy6cA

How to remove Win32/Kryptik.GHFZ?

Win32/Kryptik.GHFZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment