Malware

Win32/Kryptik.GVFD (file analysis)

Malware Removal

The Win32/Kryptik.GVFD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GVFD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Belarusian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients

Related domains:

startprojekt.xyz

How to determine Win32/Kryptik.GVFD?


File Info:

crc32: 84FDE522
md5: 11800892ea31be47eaf6de01f73e992c
name: upload_file
sha1: ad8963bf393bd2adeacac7e4802a1f6e9f742bfa
sha256: 56b80e17b37e729d37f4019ba8bab91fd812616eac95ec03e2c12566d2313e3b
sha512: 2d4a821844bcffdb6d1c51eb13eb27868df57c3755853a10d4682a708fc3dac7ca46bdaba0098565f32aaaaa410a90e17a428d73eb23be93a09eecb9eaa2b52e
ssdeep: 6144:4MFHSiGu5DpLHC38LU0DdniaoZzEKEdHujFSMNqLydNj4S8hvrGuSGGu7VWiQ1d:ZnRhNdxFuj7ZQDhvnZVWT1dvfR5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, mhchfkh
InternalName: ytereth.exe
ProductVersion: 1.9.1
Translation: 0x0847 0x03fc

Win32/Kryptik.GVFD also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.32213360
FireEyeGeneric.mg.11800892ea31be47
CAT-QuickHealRansom.Stop.MP4
McAfeeArtemis!11800892EA31
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.32213360
K7GWTrojan ( 00554d101 )
K7AntiVirusTrojan ( 00554d101 )
TrendMicroTrojan.Win32.SODINOK.SM.hp
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.32213360
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanPSW:Win32/Predator.051397c4
NANO-AntivirusTrojan.Win32.Predator.fvbfpd
AegisLabTrojan.Win32.Predator.i!c
TencentWin32.Trojan.Generic.Dwjg
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.32213360 (B)
ComodoMalware@#2ptqnf9w9q03t
F-SecureHeuristic.HEUR/AGEN.1107506
DrWebTrojan.PWS.Siggen2.25909
ZillyaTrojan.Kryptik.Win32.1874412
Invinceaheuristic
Trapminemalicious.high.ml.score
SophosMal/GandCrab-H
IkarusTrojan.Krypt
JiangminTrojan.Generic.elhyn
AviraHEUR/AGEN.1107506
MAXmalware (ai score=100)
ArcabitTrojan.Generic.D1EB8970
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Skeeyah.B!rfn
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MalPe31.Suspicious.X2022
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.GenericKD.32213360
Ad-AwareTrojan.GenericKD.32213360
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GVFD
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Wacatac!8.10C01 (CLOUD)
eGambitUnsafe.AI_Score_91%
FortinetW32/Kryptik.GWIV!tr
BitDefenderThetaGen:NN.ZexaF.34130.Dy0@aqnGTEgG
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.2.F18B.Malware.Gen

How to remove Win32/Kryptik.GVFD?

Win32/Kryptik.GVFD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment