Malware

Win32/Kryptik.GKZF removal tips

Malware Removal

The Win32/Kryptik.GKZF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GKZF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GKZF?


File Info:

crc32: 8DAE4AC5
md5: ff3ec60cf12d25ba5f1f0294fbc1ec99
name: FF3EC60CF12D25BA5F1F0294FBC1EC99.mlw
sha1: 7ff1818edd67c9f3ee7155a1a05b51ee9832917d
sha256: 921aba71d83bc98fc01de5137e17fdc9f81b980f34787a30d255cc09d09b7441
sha512: 9c58fb0d69d3fda5fb367fb54bf179bfc7b8d66a63e815b90cb103c26202edb87135f8c6aef7b72f209ede1d010508fbf5d0790476993acc7826251a92ebd049
ssdeep: 3072:Ygq4R/N3khvwRQetXSey8/twHWqLHa1s1M1QA4oHn20G5717omIBN/9j:YgBR/N3kuR5tCot9U6KIQfoW97F8D
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GKZF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25976
MicroWorld-eScanTrojan.Brsecmon.1
ALYacTrojan.Ransom.GandCrab
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/GandCrypt.ab5cdce5
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.cf12d2
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKZF
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.GandCrypt.fiejof
ViRobotTrojan.Win32.R.Agent.179200.AL
TencentMalware.Win32.Gencirc.114d4e7b
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-R + Mal/Kryptik-CQ
ComodoTrojWare.Win32.PSW.Coins.AF@7vd5q2
BitDefenderThetaGen:NN.ZexaF.34678.kuW@aSIKlRnO
TrendMicroTrojanSpy.Win32.CLIPBANKER.SMB
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.ff3ec60cf12d25ba
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.nc
AviraHEUR/AGEN.1121586
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/IcedId.PVS!MTB
AegisLabTrojan.Win32.GandCrypt.4!c
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.Gandcrab.R245434
Acronissuspicious
McAfeeTrojan-FPYT!FF3EC60CF12D
MAXmalware (ai score=100)
VBA32BScope.TrojanBanker.NeutrinoPOS
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SMB
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!7EFvYaovmUI
IkarusTrojan.Crypt
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Win32/Kryptik.GKZF?

Win32/Kryptik.GKZF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment