Malware

What is “Win32/Kryptik.GKWT”?

Malware Removal

The Win32/Kryptik.GKWT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GKWT virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
static.16.249.201.195.clients.your-server.de
a.tomx.xyz
ocsp.comodoca.com
ocsp.usertrust.com

How to determine Win32/Kryptik.GKWT?


File Info:

crc32: 02140D3D
md5: 540884fa56881eb44275d9defaec61fe
name: 232C9E20FB2FE2EADB44574D3B87F6E7.mlw
sha1: 1bb72c26fcc7f1aad68221fdf4fdc335fee3e30c
sha256: deaa82752506b1b631f2c0a28ce54f9a7311a7bc709adb74a768b3857622fac5
sha512: 9e7518e0f6659b56b53bde234d7b73a6cd1c0b3980cf2d7271d6b419fc19b6587f9a092684d30c21758e6ca14be0f8606bd25768cf6261abb5a7ef816c2c1094
ssdeep: 49152:7/xHAtt5Hg3rTCUby8whFoDC0IOQ13lu:7JHKtZ8yhnAXm3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 15.0.26126.20
ProductName: AFComp.EXE
FileVersion: 15.0.26126.20
CompanyName: AFComp
Translation: 0x0409 0x04e3

Win32/Kryptik.GKWT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053e8521 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3673
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Ekstak.S3560696
ALYacApplication.Bundler.ICLoader.5.Gen
CylanceUnsafe
ZillyaAdware.Ekstak.Win32.8
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Ekstak.371d78d3
K7GWTrojan ( 0053e8521 )
Cybereasonmalicious.a56881
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GKWT
APEXMalicious
AvastWin32:ICLoader-X [Adw]
ClamAVWin.Packed.Icloader-7057426-0
KasperskyTrojan.Win32.Ekstak.jddb
BitDefenderApplication.Bundler.ICLoader.5.Gen
NANO-AntivirusTrojan.Win32.Katusha.fhxwpb
MicroWorld-eScanApplication.Bundler.ICLoader.5.Gen
TencentWin32.Trojan.Ekstak.Ssgu
Ad-AwareApplication.Bundler.ICLoader.5.Gen
SophosGeneric PUA BL (PUA)
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34170.Mr0@a4DNKtei
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.540884fa56881eb4
EmsisoftApplication.Bundler.ICLoader.5.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.dxic
WebrootW32.Adware.Gen
AviraTR/ICLoader.Gen8
Antiy-AVLTrojan/Generic.ASMalwS.28128BE
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitApplication.Bundler.ICLoader.5.Gen
ZoneAlarmTrojan.Win32.Ekstak.jddb
GDataApplication.Bundler.ICLoader.5.Gen
AhnLab-V3PUP/Win32.ICLoader.R237626
Acronissuspicious
McAfeePacked-FMV!540884FA5688
VBA32BScope.Trojan.InstallCube
MalwarebytesICLoader.Adware.Bundler.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!iKlnsnzZvu8
IkarusPUA.ICLoader
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GKWT?

Win32/Kryptik.GKWT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment