Malware

Win32/Kryptik.GTKF malicious file

Malware Removal

The Win32/Kryptik.GTKF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GTKF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

bestbtcchange.com
ip-api.com

How to determine Win32/Kryptik.GTKF?


File Info:

crc32: FD758DF0
md5: c4d54ae0e5f00661523f777c77a234e0
name: C4D54AE0E5F00661523F777C77A234E0.mlw
sha1: af2a2f30b69295d6916c9db190c2916f3f357edc
sha256: 8c18ee53f738c160e6d943af79a2810b8bcd8160c7e975351602df691f017aa3
sha512: fc3d011baed1b6b59b7d6cd20ac84def406ac7a4a2440a292acf631479f8a0eee1c5778808f16cddeb6612d44dad512d49505551648c6e19e0bf505404e626dc
ssdeep: 12288:G7QY/stL2JSKADw4ZorfmYqjjkrkrPbZVUaViIXlEIRbK:GMMYeqDw4ZoFgjWQEP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GTKF also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.29188
CynetMalicious (score: 100)
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
ZillyaTrojan.Generic.Win32.833609
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GandCrab.f9fac5b5
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.0e5f00
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GTKF
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Chapak.fqpjsh
SUPERAntiSpywareHack.Tool/Gen-BitCoinMiner
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan.Chapak.Szuz
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.Ransom.GandCrab.ASA@8bmkty
BitDefenderThetaGen:NN.ZexaF.34770.LyW@a8AOtKb
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionSodinokibi!C4D54AE0E5F0
FireEyeGeneric.mg.c4d54ae0e5f00661
EmsisoftTrojan.BRMon.Gen.4 (B)
JiangminTrojan.Chapak.dqm
AviraHEUR/AGEN.1136564
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.2BAB757
MicrosoftRansom:Win32/GandCrab.AF!MTB
AegisLabTrojan.Win32.NeutrinoPOS.4!c
GDataTrojan.BRMon.Gen.4
AhnLab-V3Malware/Win32.Generic.R273844
Acronissuspicious
McAfeeSodinokibi!C4D54AE0E5F0
VBA32BScope.TrojanBanker.NeutrinoPOS
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@ML.86 (RDML:3cgptN1kxUuHxHz1UexhxQ)
YandexTrojan.Chapak!hCKv3A2pUhw
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74345216.susgen
FortinetW32/GenKryptik.DJEQ!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOMA

How to remove Win32/Kryptik.GTKF?

Win32/Kryptik.GTKF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment