Malware

Win32/Kryptik.GNKP removal

Malware Removal

The Win32/Kryptik.GNKP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GNKP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Detects the presence of Wine emulator via function name
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

slpsrgpsrhojifdij.ru
sruhsuirghurhgud.ru
siusiehfusguiriu.ru
fsuesuuuesheuhfu.ru
rsiiuisuiuiuidui.ru
eeifiifigginsish.ru
eifusieuuusususu.ru
aiiiaiifhfugugud.ru
ueusifhsiheadhih.ru
unokaoeojoejfghr.ru
siiiifejijsirjgi.ru
aaiiaiaiaiishihg.ru
aaaaaaaofoofofgh.ru
ommmononafagoake.ru
iiiiaeieifihgihi.ru
aaaaaaaueieieiii.ru
aaaaaaaauhguhifi.ru
ollsorshsrhijfij.ru
koooooookoeoirif.ru
abucuabuheuahehu.ru
bbbuuusuuhisgijs.ru
ibseyhefrjifsrgg.ru
yuhujishruuhtuhu.ru
aaiiehiehueudhuh.ru
niursosokforhoht.ru
sruhsuirghurhgud.su
siusiehfusguiriu.su
fsuesuuuesheuhfu.su
rsiiuisuiuiuidui.su
eeifiifigginsish.su
eifusieuuusususu.su
aiiiaiifhfugugud.su
ueusifhsiheadhih.su
unokaoeojoejfghr.su
siiiifejijsirjgi.su
aaiiaiaiaiishihg.su
aaaaaaaofoofofgh.su
ommmononafagoake.su
iiiiaeieifihgihi.su
aaaaaaaueieieiii.su
aaaaaaaauhguhifi.su
ollsorshsrhijfij.su
koooooookoeoirif.su
abucuabuheuahehu.su
bbbuuusuuhisgijs.su
ibseyhefrjifsrgg.su
yuhujishruuhtuhu.su
aaiiehiehueudhuh.su

How to determine Win32/Kryptik.GNKP?


File Info:

crc32: 832FA930
md5: a52d94cf381da5df0462692db50c696d
name: A52D94CF381DA5DF0462692DB50C696D.mlw
sha1: af82d8eda5ee89bbba2be1c07d5f6701232d289c
sha256: 6add193fbc3a7fcf70370e5e25b57c5c1c5edd862410f61f9af9a0dbebe11b13
sha512: 1fec32d224cbe582016ee643154b9b63bcafe854af002440062b59cdcfc347218a3604d0173c81bce90973570a15080b7e581cc067283c030b0473c952a344e4
ssdeep: 1536:wmppsL/7HN8Suw7oi4SLf04LrdEv5FkjbGBYls4A3xNJ/:XpKLzKqx5Ev5FkjbG6VAbJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, whxofirr
InternalName: siyyajhi.ehi
FileVersion: 1.3.6
ProductVersion: 1.0.4.11

Win32/Kryptik.GNKP also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00543e471 )
LionicTrojan.Win32.Zenpak.4!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner2.48480
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Tiggre.S4565990
ALYacGen:Variant.Ranpack.3
CylanceUnsafe
ZillyaTrojan.Bayrob.Win32.33566
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Gandcrab.130c6e1f
K7GWTrojan ( 00543e471 )
Cybereasonmalicious.f381da
CyrenW32/Kryptik.NH.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GNKP
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Chapak-7489442-0
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderGen:Variant.Ranpack.3
NANO-AntivirusTrojan.Win32.Bayrob.fkwfyy
ViRobotTrojan.Win32.Agent.1532416
MicroWorld-eScanGen:Variant.Ranpack.3
TencentMalware.Win32.Gencirc.114d78ee
Ad-AwareGen:Variant.Ranpack.3
SophosMal/Generic-R + Mal/GandCrab-D
ComodoTrojWare.Win32.Ransom.Gandcrab.AO@7zf1nr
BitDefenderThetaGen:NN.ZexaF.34796.Du0@aCQqJjne
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Emotet.gz
FireEyeGeneric.mg.a52d94cf381da5df
EmsisoftTrojan.Crypt (A)
JiangminTrojan.Chapak.aez
AviraHEUR/AGEN.1102740
Antiy-AVLTrojan/Generic.ASMalwS.29C6F66
MicrosoftTrojan:Win32/Gandcrab.VRD!MTB
SUPERAntiSpywareRansom.GandCrab/Variant
GDataGen:Variant.Ranpack.3
AhnLab-V3Win-Trojan/MalPe4.Suspicious.X1939
McAfeePacked-FPI!A52D94CF381D
MAXmalware (ai score=100)
VBA32BScope.Trojan.Fuery
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Kryptik!1.B50A (CLASSIC)
YandexTrojan.GenAsa!BKyIT5Zap9k
IkarusTrojan.Win32.Gandcrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CUPF!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCPkUA

How to remove Win32/Kryptik.GNKP?

Win32/Kryptik.GNKP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment