Malware

About “Win32/Kryptik.GKFM” infection

Malware Removal

The Win32/Kryptik.GKFM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GKFM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

oneteenager.com
www.btwordpress.xyz
www.hologramrawmaterial.com
petirnews.com
www.scheckin.com
www.alltest.pl
hifipig.com
2ndeye.com
www.xn--80adgp0a.xn--p1ai
mubara.net

How to determine Win32/Kryptik.GKFM?


File Info:

crc32: A8BCB4B6
md5: e83678d7a93d2f1decdb689618b3f475
name: E83678D7A93D2F1DECDB689618B3F475.mlw
sha1: 554c009abdc78b7175ce552db39aaf296c311502
sha256: 9d3603aa46b2459bb7589e2615c71b84d7e25e635e1b70b11a42d4f2b4f54aae
sha512: 91ac4d4dd84097d32b1a44b59107133ab83904df64f5a4bb8a8d97e7e5cdcbd54c2614010d5901926f80e110619b75cde52068519ebdf9c4bd79a5d8f9a6d80f
ssdeep: 1536:r0NdEic7zbwOdEJ/Wvx8CTKgGq5ZRWP/fa0MU/qcFhg1jFhpkaDnJ90cDEcdfsv7:rfVhKCEa/IZgJLaaDnJmEJ45
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GKFM also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053b4261 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.35877
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31182354
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.168821
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojanBanker:Win32/ClipBanker.35f31c41
K7GWTrojan ( 0053b4261 )
Cybereasonmalicious.7a93d2
SymantecRansom.Hermes!gen3
ESET-NOD32a variant of Win32/Kryptik.GKFM
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Banker.Win32.ClipBanker.bk
BitDefenderTrojan.GenericKD.31182354
NANO-AntivirusTrojan.Win32.Kryptik.fhbmub
MicroWorld-eScanTrojan.GenericKD.31182354
TencentMalware.Win32.Gencirc.114d2829
Ad-AwareTrojan.GenericKD.31182354
SophosMal/Generic-S
ComodoMalware@#ydfvbhm2k4mk
BitDefenderThetaGen:NN.ZexaF.34690.smW@aahy6ecG
TrendMicroRansom.Win32.BITPAYMER.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.e83678d7a93d2f1d
EmsisoftTrojan.GenericKD.31182354 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.ClipBanker.h
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1131446
eGambitUnsafe.AI_Score_67%
Antiy-AVLTrojan/Generic.ASMalwS.27DCE7E
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmTrojan-Banker.Win32.ClipBanker.bk
GDataTrojan.GenericKD.31182354
AhnLab-V3Trojan/Win32.Cloxer.C2690060
Acronissuspicious
McAfeeGenericRXGI-YJ!E83678D7A93D
MAXmalware (ai score=78)
VBA32BScope.Trojan.Fuerboos
MalwarebytesMalware.AI.3750304246
PandaTrj/CI.A
TrendMicro-HouseCallRansom.Win32.BITPAYMER.SM.hp
RisingDownloader.Godzilla!8.E3AB (CLOUD)
YandexTrojan.GenAsa!41LKSqJQ0x0
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.GKQG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GKFM?

Win32/Kryptik.GKFM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment