Malware

Win32/Kryptik.GTRL removal

Malware Removal

The Win32/Kryptik.GTRL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GTRL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.GTRL?


File Info:

name: 4EC4158E0C0C920ED3D4.mlw
path: /opt/CAPEv2/storage/binaries/793988642e9db44a74c5840b00d1f6a293e82386f4a857b8323dd221b3a7b208
crc32: 98092DBB
md5: 4ec4158e0c0c920ed3d472668fcd344e
sha1: 813145989b30afe8669a167b8123e7e636291811
sha256: 793988642e9db44a74c5840b00d1f6a293e82386f4a857b8323dd221b3a7b208
sha512: f3308b3bc8184ddd0cd221274bbb035478aff5dcec12e198ac6cd8c45d865cd33e7590b6373742bdacdacbcb873632dbd51a604965732be247eccd91dacd4060
ssdeep: 24576:HNbQYw3P7C7anmGxDAi05OxGpf0Tu2Xillh0DA:tbQYwrn1AR5UXTXillp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11005E02336D0C431C5734272096ABB0146FFBC725D719BDB67E85A8E5B389C2AA27317
sha3_384: 663646d8db9e814d6c30b849f5bcb16a0b06e31b79a2195fa8e0787e473ce44f3054fde909578e8045d0f513eb5a7e72
ep_bytes: e846d60000e939feffff558bec568b75
timestamp: 2018-09-07 14:27:51

Version Info:

0: [No Data]

Win32/Kryptik.GTRL also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.17140
CynetMalicious (score: 100)
FireEyeGeneric.mg.4ec4158e0c0c920e
McAfeeArtemis!4EC4158E0C0C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Brsecmon.1
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Chapak.d61b9dae
K7GWTrojan ( 0054f8dc1 )
K7AntiVirusTrojan ( 0054f8dc1 )
BitDefenderThetaGen:NN.ZexaF.34182.1uW@autve!
CyrenW32/Agent.BAY.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GTRL
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
Paloaltogeneric.ml
KasperskyTrojan.Win32.Chapak.dljf
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Chapak.fsqdrm
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanTrojan.Brsecmon.1
AvastFileRepMalware
TencentWin32.Trojan.Chapak.Phqq
EmsisoftTrojan.Brsecmon.1 (B)
ComodoTrojWare.Win32.Ransom.GandCrab.AVA@8cc3d7
ZillyaTrojan.Kryptik.Win32.3628922
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-R + Mal/GandCrab-G
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1106537
Antiy-AVLTrojan/Generic.ASMalwS.2BD4FF1
MicrosoftPWS:Win32/Vidar.YC!rfn
ZoneAlarmTrojan.Win32.Chapak.dljf
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win32.BlueCrab.R274565
VBA32TrojanPSW.Vidar
ALYacTrojan.Brsecmon.1
MAXmalware (ai score=100)
MalwarebytesTrojan.MalPack.GS.Generic
APEXMalicious
RisingRansom.Sodinokibi!1.B930 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74361285.susgen
FortinetW32/Kryptik.GTQM!tr
AVGFileRepMalware
Cybereasonmalicious.e0c0c9
PandaTrj/Genetic.gen

How to remove Win32/Kryptik.GTRL?

Win32/Kryptik.GTRL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment