Malware

Win32/Kryptik.GTWE removal guide

Malware Removal

The Win32/Kryptik.GTWE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GTWE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Sanskrit
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

aiiesspress.com
ip-api.com

How to determine Win32/Kryptik.GTWE?


File Info:

crc32: 3E7691B1
md5: de008dc53026bbee7f4497de30308fe2
name: DE008DC53026BBEE7F4497DE30308FE2.mlw
sha1: 09ca227341c63e865a603cca1f6d8ef5eab2b68e
sha256: a5b7899140a161775c3c95f1dac0de3962c76277e4d5e1a6fd359a2ac2b3713a
sha512: 1183bcf4604bced7a87a8decaa73bb1298eea2e6d4e555a5f085914b83708ad3bf450bf457735697812aa0d0c86b206a63b26cf0dd12e7e85d467ca2368c2331
ssdeep: 12288:xV5ZeEWO8QOSzMgY3bqoR94m11D4jBv7Umg9zqNehot6:xV5wEtoSzMJ2jO18QmgcNeK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GTWE also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.12561
CAT-QuickHealRansom.Stop.J3
ALYacTrojan.Brsecmon.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Mufila.30b7c9d7
K7GWTrojan ( 0054ff251 )
K7AntiVirusTrojan ( 0054ff251 )
CyrenW32/Dofoil.I.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GTWE
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Kryptik.hivogs
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Brsecmon.Wrpw
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-S
ComodoTrojWare.Win32.Fakecsrss.AV@88nqyj
F-SecureTrojan.TR/AD.VidarStealer.alxr
BitDefenderThetaGen:NN.ZexaF.34170.OuW@aSqI3aaG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.de008dc53026bbee
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.VidarStealer.alxr
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2FE034D
MicrosoftTrojan:Win32/Mufila.DSK!MTB
ArcabitTrojan.Brsecmon.1
GDataTrojan.Brsecmon.1
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
McAfeeSodinokibi!DE008DC53026
MAXmalware (ai score=83)
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Generic@ML.100 (RDMK:JOEudBJRVymgml2/mwgyqg)
IkarusTrojan-PSW.Agent
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.DQHN!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.GTWE?

Win32/Kryptik.GTWE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment