Malware

Win32/Kryptik.GXTG information

Malware Removal

The Win32/Kryptik.GXTG file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Kryptik.GXTG virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GXTG?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: Riskware ( 0040eff71 )

File Info:

Name: wordupd.tmp

Size: 724480

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: 0f841c6332c89eaa7cac14c9d5b1d35b

SHA1: 23acd12dd10615c5f0604e842d755a0ee3f4b42e

SH256: 806fc33650b7ec35dd01a06be3037674ae3cc0db6ba1e3f690ee9ba9403c0627

Version Info:

[No Data]

Win32/Kryptik.GXTG also known as:

ALYacTrojan.Ransom.ChaCha
APEXMalicious
AVGWin32:Malware-gen
Acronissuspicious
Ad-AwareTrojan.GenericKD.41962973
AhnLab-V3Malware/Win32.Generic.C3537701
AlibabaTrojanSpy:Win32/Zbot.78519356
Antiy-AVLTrojan[Spy]/MSIL.Zbot
ArcabitTrojan.Generic.D2804DDD
AvastWin32:Malware-gen
AviraTR/AD.MazeRansom.gvzeo
BitDefenderTrojan.GenericKD.41962973
BitDefenderThetaGen:NN.ZexaF.32253.SuW@a8OGdwmO
CAT-QuickHealTrojanSpy.MSIL
ComodoMalware@#23y4qdr9k18hb
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.dd1061
CylanceUnsafe
CyrenW32/Trojan.ETCH-6770
DrWebTrojan.Encoder.29921
ESET-NOD32a variant of Win32/Kryptik.GXTG
EmsisoftTrojan.GenericKD.41962973 (B)
Endgamemalicious (high confidence)
F-SecureTrojan.TR/AD.MazeRansom.gvzeo
FireEyeGeneric.mg.0f841c6332c89eaa
FortinetW32/Kryptik.GVFO!tr
GDataTrojan.GenericKD.41962973
IkarusTrojan.Win32.Krypt
Invinceaheuristic
JiangminTrojanSpy.MSIL.ajda
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
KasperskyTrojan-Spy.MSIL.Zbot.psn
MAXmalware (ai score=81)
MalwarebytesRansom.Maze
MaxSecureTrojan.Malware.74664575.susgen
McAfeeTrojan-Ransom.e
McAfee-GW-EditionBehavesLike.Win32.Downloader.bm
MicroWorld-eScanTrojan.GenericKD.41962973
MicrosoftTrojan:Win32/Occamy.C
NANO-AntivirusTrojan.Win32.Zbot.ggcbfe
Paloaltogeneric.ml
PandaTrj/CI.A
Qihoo-360HEUR/QVM19.1.E187.Malware.Gen
RisingStealer.Delf!8.415 (TFE:2:Z1Y6pjxI2fS)
SentinelOneDFI – Malicious PE
SophosMal/EncPk-AOR
SymantecTrojan Horse
Trapminemalicious.moderate.ml.score
TrendMicroTROJ_FRS.VSNW1EJ19
TrendMicro-HouseCallTROJ_FRS.VSNW1EJ19
VBA32Malware-Cryptor.General.3
VIPRETrojan.Win32.Generic!BT
ViRobotTrojan.Win32.Maze.724480
WebrootW32.Ransom.Maze
YandexTrojanSpy.Zbot!Dv7IGQhpFQM
ZillyaTrojan.Kryptik.Win32.1817999
ZoneAlarmTrojan-Spy.MSIL.Zbot.psn

How to remove Win32/Kryptik.GXTG?

Win32/Kryptik.GXTG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment