Malware

Should I remove “Win32/Kryptik.GRKC”?

Malware Removal

The Win32/Kryptik.GRKC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GRKC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Zulu
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Win32/Kryptik.GRKC?


File Info:

name: 1074313C71AA6A495ADA.mlw
path: /opt/CAPEv2/storage/binaries/95d52fd04e7a1544061eca8c78c34eca6cefa630f8d8f90757123a44f9675b57
crc32: ED64FA80
md5: 1074313c71aa6a495ada5ae39029eb8a
sha1: 5c7935e315433590f6338e183735bc4fc8f2cde6
sha256: 95d52fd04e7a1544061eca8c78c34eca6cefa630f8d8f90757123a44f9675b57
sha512: 8c842f87dec503fd1ea6d86ef8a7e8fdf90f52ab14edc6010a9ce7ebcd7026798a0ef7d81cd0c63dfc1f6ed5e80bef99b3bcb50c58fc913ac2ecdab14f91848e
ssdeep: 6144:PWf7EgRnk8Wj/v9Z3mRNqNdv/8apMkFvmr:PWf7PnOj/vr3mRNg9BpMaY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195546C46F2CA2D50C37415FD700FAFBAD051D922AC25E281D7BF1B43D5B8F1027A66AA
sha3_384: a49996192516e326bb345b3efe1a277ffceaa8921d58232900afe6db258359af895fd1e79e2b6f98183dcccc9a32b8c4
ep_bytes: 60be003076058dbe00e0c9fa5783cdff
timestamp: 2018-01-01 18:02:53

Version Info:

0: [No Data]

Win32/Kryptik.GRKC also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.31830863
FireEyeGeneric.mg.1074313c71aa6a49
ALYacTrojan.GenericKD.31830863
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.73501
K7AntiVirusTrojan ( 0054ac421 )
AlibabaTrojan:Win32/Chapak.f8fbbdba
K7GWTrojan ( 0054ac421 )
Cybereasonmalicious.c71aa6
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GRKC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Chapak.clvl
BitDefenderTrojan.GenericKD.31830863
NANO-AntivirusTrojan.Win32.Chapak.forfrq
AvastWin32:Malware-gen
TencentWin32.Trojan.Chapak.Dvps
Ad-AwareTrojan.GenericKD.31830863
SophosMal/Generic-S
ComodoMalware@#3n6v980e4h37g
DrWebTrojan.DownLoader27.42575
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.TIOIBOCC
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.GenericKD.31830863 (B)
IkarusTrojan.Win32.Crypt
GDataTrojan.GenericKD.31830863
JiangminTrojan.Generic.dddyj
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1107509
Antiy-AVLTrojan/Generic.ASMalwS.2B06AA0
ArcabitTrojan.Generic.D1E5B34F
ViRobotTrojan.Win32.GandCrab.Gen.B
MicrosoftTrojan:Win32/Skeeyah.B!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fuerboos.R260973
Acronissuspicious
McAfeeArtemis!1074313C71AA
MAXmalware (ai score=100)
VBA32BScope.Trojan.Azden
TrendMicro-HouseCallRansom.Win32.GANDCRAB.TIOIBOCC
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!tDPjrZLAu/U
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_86%
FortinetW32/CoinMiner.HGHW!tr
BitDefenderThetaGen:NN.ZexaF.34294.rmGfauJpEXjK
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Kryptik.GRKC?

Win32/Kryptik.GRKC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment