Malware

Win32/Kryptik.GITV removal tips

Malware Removal

The Win32/Kryptik.GITV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GITV virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system

Related domains:

static.43.47.69.159.clients.your-server.de

How to determine Win32/Kryptik.GITV?


File Info:

crc32: 1BED1229
md5: c6a78bc4e3b825381cd13009000826fb
name: C6A78BC4E3B825381CD13009000826FB.mlw
sha1: 7cd91112c736a22f5068132b8a09acdf10fdd0cf
sha256: 1a1be31fe668afc1486c8cd7107f2218b61772e66bcfab0a22eef4a5dc87bcf0
sha512: b531098b9736ea776be026e4acca25ceb5d21ac44f2c515826a4997978a9c2bcef0bef50ccedf121c9f4dd9085dd90d7df5cdb8fe378a953f728e652732c29a2
ssdeep: 12288:96dIBE7AU1o1JPlK1dWPXUb9/eY8vQpBNSl6mktgYfk2nIarSQjdd3XN:96dIm7yPexp/RrSlGgKkaRuOdpN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 6.1.7601.23834
InternalName: HelpPane.exe
FileVersion: 6.1.7601.23834 (win7sp1_ldr.170601-2259)
OriginalFilename: HelpPane.exe
FileDescription: Help and Support
Translation: 0x0409 0x04b0

Win32/Kryptik.GITV also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00535dd71 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3635
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S18992558
ALYacApplication.Bundler.ICLoader.4.Gen
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3136541
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Katusha.84c7cc60
K7GWTrojan ( 00535dd71 )
Cybereasonmalicious.4e3b82
CyrenW32/S-1cdeceaf!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GITV
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyUDS:Trojan.Win32.Ekstak.a
BitDefenderApplication.Bundler.ICLoader.4.Gen
NANO-AntivirusTrojan.Win32.InstallCube.ffgjhv
MicroWorld-eScanApplication.Bundler.ICLoader.4.Gen
TencentTrojan.Win32.Kryptik.gitv
Ad-AwareApplication.Bundler.ICLoader.4.Gen
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-FHK!C6A78BC4E3B8
FireEyeGeneric.mg.c6a78bc4e3b82538
EmsisoftApplication.AdFile (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.ICLoader.jzt
AviraTR/ICLoader.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.2707B4A
MicrosoftSoftwareBundler:Win32/ICLoader
ArcabitApplication.Bundler.ICLoader.4.Gen
GDataWin32.Application.Asik.A
AhnLab-V3PUP/Win32.ICLoader.R232095
Acronissuspicious
McAfeePacked-FHK!C6A78BC4E3B8
MAXmalware (ai score=98)
VBA32Backdoor.IRCBot
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!UJFnR1bLEDI
IkarusPUA.ICLoader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]

How to remove Win32/Kryptik.GITV?

Win32/Kryptik.GITV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment