Malware

Win32/Kryptik.GTKI removal instruction

Malware Removal

The Win32/Kryptik.GTKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GTKI virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GTKI?


File Info:

crc32: 24230D5C
md5: 1df8c14bd3b4ba81c0510a1cd9212295
name: 1DF8C14BD3B4BA81C0510A1CD9212295.mlw
sha1: 650be479fe7124b858ad84eac0292d2e1f09b8b3
sha256: 9159fe1bb9da29eec6b39a4476f29ee90ad40935348d7ddbdb30d62d3151e8c3
sha512: dffd5eafea1353e1101d7b54c1a614d5a2d9acb4b59631b8f03294d2d4ef0296afe82127c39d3077edddf731556ecd9597febb1807ef2c1b3cf3dc95885b92b8
ssdeep: 1536:FKLmdtIonPKyi9GH43qatbBoEAqLxyFlXD1I/Zk:FKLUk9GReV7xS5D1I/Zk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: TeamViewer GmbH
InternalName: tv_loader
FileVersion: 7.0.12979.0
CompanyName: TeamViewer GmbH
ProductName: TeamViewer
ProductVersion: 7.0
FileDescription: Helper process for TeamViewer performance optimization and QuickConnect
OriginalFilename: tv_w32.exe
Translation: 0x0000 0x04b0

Win32/Kryptik.GTKI also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Bunitu-7641474-0
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeTrickbot-FRDP!1DF8C14BD3B4
CylanceUnsafe
ZillyaTrojan.NetStream.Win32.251
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0053d9731 )
K7AntiVirusTrojan ( 0053d9731 )
CyrenW32/Trojan.BUF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GTKI
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Jamg.1
NANO-AntivirusTrojan.Win32.NetStream.fllmyp
MicroWorld-eScanGen:Heur.Mint.Jamg.1
TencentMalware.Win32.Gencirc.10ba44cb
Ad-AwareGen:Heur.Mint.Jamg.1
SophosMal/Generic-S + Mal/Cerber-AM
ComodoTrojWare.Win32.TrojanProxy.Bunitu.JL@80mh7b
BitDefenderThetaGen:NN.ZexaF.34678.tq1@a0MUeMA
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.SHADE.SMB.hp
McAfee-GW-EditionTrickbot-FRDP!1DF8C14BD3B4
FireEyeGeneric.mg.1df8c14bd3b4ba81
EmsisoftGen:Heur.Mint.Jamg.1 (B)
AviraHEUR/AGEN.1105585
MicrosoftTrojan:Win32/GandCrab.KDV!MTB
ArcabitTrojan.Mint.Jamg.1
AegisLabTrojan.Win32.NetStream.4!c
GDataGen:Heur.Mint.Jamg.1
AhnLab-V3Trojan/Win32.Kryptik.C2903035
VBA32BScope.Trojan.NetStream
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3912797216
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom.Win32.SHADE.SMB.hp
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!weUkNFYlLWE
IkarusTrojan-Ransom.Crypted007
FortinetW32/Kryptik.GLWT!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Win32/Kryptik.GTKI?

Win32/Kryptik.GTKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment