Malware

Win32/Kryptik.GUFP removal

Malware Removal

The Win32/Kryptik.GUFP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GUFP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Ursnif3 malware family

How to determine Win32/Kryptik.GUFP?


File Info:

name: D03A4F5ABE81827FDACF.mlw
path: /opt/CAPEv2/storage/binaries/685a702b80118d7d27d903b87e4c1f74e5dc53d438fa883bcc3bf4cfcaaa9093
crc32: 94EA4248
md5: d03a4f5abe81827fdacfb4e6097eb23f
sha1: 850cd4875ebd6a74b3f8cb70f6e039b5e10b1e29
sha256: 685a702b80118d7d27d903b87e4c1f74e5dc53d438fa883bcc3bf4cfcaaa9093
sha512: d3cafda7a1df3d35768045808cd7f02f0da38ce8c9b502c8be61758d75a638b510ff53fda336ca454b0c2081569223bc83bc8ef4797f7f5fbfd636293fbe9bed
ssdeep: 12288:1V3BBccxdqbp+lCPuYMJcpxD4fibfDvl:XVy+lUuY8qxDKap
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BEE4E6336E919C6CE4AACEF41AAA41655C68EE50BF3080CB258131DA45FD9D07B3DED3
sha3_384: 569e53ad365a5159656d0195747ffc4630a738ab133fadccc63c316ff8b396409b6769f21f2e761b1d05ed3cdb8a003b
ep_bytes: 558bece858fdffff5dc3cccccccccccc
timestamp: 2016-06-24 11:04:30

Version Info:

CompanyName: Netpeak Piecething
FileDescription: Whycompany Parentthan
FileVersion: 14.4.93.50 Duringfour
InternalName: devenv.exe
LegalCopyright: © Netpeak Piecething.All rights reserved.
OriginalFilename: An.exe
ProductName: Whycompany Parentthan
ProductVersion: 14.4.93.50
Translation: 0x0409 0x04b0

Win32/Kryptik.GUFP also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Gozi.10!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.53
ClamAVWin.Malware.Ursnif-7001379-1
FireEyeGeneric.mg.d03a4f5abe81827f
McAfeeGenericRXIX-GN!D03A4F5ABE81
CylanceUnsafe
VIPREGen:Heur.Mint.Zard.53
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00550b4a1 )
AlibabaTrojanBanker:Win32/Kryptik.e9f0569c
K7GWTrojan ( 00550b4a1 )
CrowdStrikewin/malicious_confidence_100% (W)
ESET-NOD32a variant of Win32/Kryptik.GUFP
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Banker.Win32.Gozi.div
BitDefenderGen:Heur.Mint.Zard.53
NANO-AntivirusTrojan.Win32.Gozi.fryudx
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b9b0eb
Ad-AwareGen:Heur.Mint.Zard.53
EmsisoftGen:Heur.Mint.Zard.53 (B)
ComodoMalware@#3rm3qr3i8oruh
DrWebTrojan.Gozi.513
ZillyaTrojan.Gozi.Win32.2391
TrendMicroTROJ_GEN.R002C0PG822
McAfee-GW-EditionGenericRXIX-GN!D03A4F5ABE81
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S + Mal/EncPk-AOY
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.Mint.Zard.53
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1210433
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.498F
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Ursnif.R278315
ALYacGen:Heur.Mint.Zard.53
TACHYONBanker/W32.Gozi.678912
VBA32TrojanBanker.Gozi
MalwarebytesMalware.AI.4239500580
TrendMicro-HouseCallTROJ_GEN.R002C0PG822
RisingTrojan.Kryptik!8.8 (TFE:5:T6Z9CDvQQIT)
YandexTrojan.PWS.Gozi!JhY1F9ajz9Q
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74406979.susgen
FortinetW32/Kryptik.GUFP!tr
BitDefenderThetaGen:NN.ZexaF.34698.PC0@aqO0wMei
AVGWin32:Malware-gen
Cybereasonmalicious.abe818
PandaTrj/GdSda.A

How to remove Win32/Kryptik.GUFP?

Win32/Kryptik.GUFP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment