Malware

About “Win32/Kryptik.GSFR” infection

Malware Removal

The Win32/Kryptik.GSFR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GSFR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GSFR?


File Info:

crc32: FBDF3C59
md5: 9728523aee1e96757b88afe1b8d1a12c
name: 9728523AEE1E96757B88AFE1B8D1A12C.mlw
sha1: 7c366c3e34c9bc07131d99574195c65fb733a936
sha256: e40d58a2a10f1193eca3dd40d424c8f7b6857c7a8b129cf57e8c4e281e4e5626
sha512: befc01b55345bdd3ba8db08cf73136de35470b0984e38e93d1dc42511f5311b1b706ec77c0f58f69490a955b7882a4967c8b7a809d1ffb1d72029dedc9e9bff8
ssdeep: 3072:Xlz9BQRKOvjqxED2pp4AVksTciqgGl9ki89h7Bznv9in9jStXgwB1ik5SaKhG7:Xlz9+ljqxEo6SksTciali3v9+9jSdgw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GSFR also known as:

K7AntiVirusTrojan ( 0054c3061 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Trick.46212
ClamAVWin.Trojan.Emotet-7338391-0
ALYacTrojan.Trickster.Gen
CylanceUnsafe
SangforTrojan.Win32.Trickster.cow
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/MereTam.ali2000008
K7GWTrojan ( 0054c3061 )
Cybereasonmalicious.aee1e9
CyrenW32/Trojan.LGAW-1549
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GSFR
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.Trickster.cow
BitDefenderTrojan.Autoruns.GenericKD.41399300
NANO-AntivirusTrojan.Win32.Trickster.fpgwww
MicroWorld-eScanTrojan.Autoruns.GenericKD.41399300
TencentWin32.Trojan.Raasmd.Auto
Ad-AwareTrojan.Autoruns.GenericKD.41399300
SophosMal/Generic-S + Troj/Agent-BBGH
ComodoMalware@#2gr50awdc7lh3
BitDefenderThetaGen:NN.ZexaF.34294.luW@a0klTxgi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.9728523aee1e9675
EmsisoftTrojan.Autoruns.GenericKD.41399300 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1132867
eGambitUnsafe.AI_Score_83%
Antiy-AVLTrojan/Generic.ASMalwS.2B3CDEF
MicrosoftTrojan:Win32/Skeeyah.A!bit
GDataWin32.Trojan-Spy.Trickbot.AC
AhnLab-V3Trojan/Win32.Kryptik.R270223
Acronissuspicious
McAfeeArtemis!9728523AEE1E
VBA32BScope.TrojanBanker.Trickster
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.90 (RDMK:W2tUBe49CINNdx0hC+DVdg)
YandexTrojan.PWS.Trickster!Xu7OjWj6lbs
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.74257644.susgen
FortinetW32/Kryptik.GSFR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GSFR?

Win32/Kryptik.GSFR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment