Malware

Win32/Kryptik.GNKW information

Malware Removal

The Win32/Kryptik.GNKW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GNKW virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GNKW?


File Info:

name: 53CD322158012C5C2868.mlw
path: /opt/CAPEv2/storage/binaries/53c17964ff23e4c3601ae96850900b3c0a44cdbd9f3091fb0c1d96f01175cc56
crc32: E8EEDA12
md5: 53cd322158012c5c28680bc2e69fc84a
sha1: 2c4de9a6c5332efd9fe723dc20c03c2ea6e44940
sha256: 53c17964ff23e4c3601ae96850900b3c0a44cdbd9f3091fb0c1d96f01175cc56
sha512: 3dae1dc54a5fe3d4de965301404a8afa1681e3211df2b7c97ef1483e2549285e1186660c8acfe29cda7d0275d4ebe084fdc7a2879ee475676745b261e21b78b9
ssdeep: 1536:seTtzlAQornHC+NeRoLTZgxZ31x6e0Pwa4mu1qgCEKDFpIp4qi4xfqsJqG+:YrC+A+Zgx7x6NPwBmeqg8Fp7qtnEG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164868E03C262990AEF5C97B2196B6F05EAB1FC00D26687494BD46B2CEDDD313FF85126
sha3_384: 3a1af57c556b888d134ba72dc1fd043bfa7de4bb3428ca2fbdbac9355e6658844af589b0cf54c9674bc17bed48cb729c
ep_bytes: 5589e56a048d6424a4b8fdfd0000b925
timestamp: 2014-08-04 11:46:11

Version Info:

0: [No Data]

Win32/Kryptik.GNKW also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.53cd322158012c5c
McAfeeGenericRXGQ-KF!53CD32215801
MalwarebytesMalware.Heuristic.1004
VIPRETrojan.Mint.Zamg.Q
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Mint.Zamg.Q
K7GWTrojan ( 00542c831 )
K7AntiVirusTrojan ( 00542c831 )
CyrenW32/S-fc1169fb!Eldorado
SymantecPacked.Generic.493
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GNKW
APEXMalicious
ClamAVWin.Dropper.Tofsee-8004725-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaMalware:Win32/km_24a46.None
NANO-AntivirusTrojan.Win32.GenKryptik.fkuukj
ViRobotTrojan.Win.Z.Tofsee.8388608
MicroWorld-eScanTrojan.Mint.Zamg.Q
AvastWin32:ReposFxg-F [Trj]
TencentMalware.Win32.Gencirc.10b09ded
EmsisoftTrojan.Mint.Zamg.Q (B)
DrWebBackDoor.Tofsee.192
ZillyaTrojan.Tofsee.Win32.1907
TrendMicroTrojan.Win32.ELENOOKA.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Dropper.rz
Trapminemalicious.high.ml.score
SophosMal/Elenoocka-G
SentinelOneStatic AI – Malicious PE
GDataTrojan.Mint.Zamg.Q
JiangminTrojan.Generic.cvisu
WebrootW32.Trojan.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Tofsee
XcitiumTrojWare.Win32.Danabot.B@81esby
ArcabitTrojan.Mint.Zamg.Q
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Danabot.G
GoogleDetected
AhnLab-V3Trojan/Gen.RL_Dyer.R267906
Acronissuspicious
VBA32BScope.Backdoor.Tofsee
ALYacTrojan.Mint.Zamg.Q
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.ELENOOKA.SM.hp
RisingTrojan.Fuerboos!8.EFC8 (TFE:4:kZu9Iq9dNiE)
YandexTrojan.GenAsa!x6eIjreK0k4
IkarusBackdoor.Win32.Tofsee
FortinetW32/GenKryptik.CSYJ!tr
AVGWin32:ReposFxg-F [Trj]
Cybereasonmalicious.158012
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.GNKW?

Win32/Kryptik.GNKW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment