Categories: Malware

Win32/Kryptik.GXTK malicious file

The Win32/Kryptik.GXTK file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Kryptik.GXTK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Slovak
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GXTK?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: RDN/Generic BackDoor

File Info:

Name: starticon0.exe

Size: 808448

Type: PE32 executable (GUI) Intel 80386, for MS Windows

MD5: 307c5b34037919495eb43810e867c16a

SHA1: 479ee357e4ea9430df252430a310f92d22e2a0a9

SH256: c84f1d6b8acb9807baf2a16dd480f64b307ade9b57b7a2d387a033e85cf5d83e

Version Info:

[No Data]

Win32/Kryptik.GXTK also known as:

ALYac Trojan.GenericKD.32662699
APEX Malicious
AVG FileRepMetagen [Malware]
Acronis suspicious
Ad-Aware Trojan.GenericKD.32662699
AegisLab Trojan.Win32.Bandit.tqTK
AhnLab-V3 Trojan/Win32.MalPe.R296515
Alibaba Trojan:Win32/Chapak.ccacd75d
Antiy-AVL Trojan[Backdoor]/Win32.Predator
Arcabit Trojan.Generic.D1F264AB
Avast FileRepMetagen [Malware]
Avira TR/AD.VidarStealer.cauu
BitDefender Trojan.GenericKD.32662699
BitDefenderTheta Gen:Trojan.Heur2.PPBB.3.0.XC0@c0oL48kG7d
CAT-QuickHeal Ransom.Stop.MP4
ClamAV Win.Packed.Generickdz-7357865-0
Comodo Malware@#109srza2n2cvr
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.7e4ea9
Cylance Unsafe
Cyren W32/Kryptik.ANT.gen!Eldorado
DrWeb Trojan.PWS.Stealer.27284
ESET-NOD32 a variant of Win32/Kryptik.GXTK
Emsisoft Trojan.GenericKD.32662699 (B)
Endgame malicious (high confidence)
F-Prot W32/Kryptik.ANT.gen!Eldorado
F-Secure Trojan.TR/AD.VidarStealer.cauu
FireEye Generic.mg.307c5b3403791949
Fortinet W32/GenKryptik.DWPH!tr
GData Trojan.GenericKD.32662699
Ikarus Trojan.Win32.Crypt
Invincea heuristic
Jiangmin AdWare.Generic.jyiy
K7AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky Trojan.Win32.Chapak.ebqm
MAX malware (ai score=80)
Malwarebytes Trojan.MalPack.GS
McAfee RDN/Generic BackDoor
McAfee-GW-Edition RDN/Generic BackDoor
MicroWorld-eScan Trojan.GenericKD.32662699
Microsoft Backdoor:Win32/Predator.J!MTB
Paloalto generic.ml
Panda Trj/GdSda.A
Qihoo-360 Win32/Trojan.63c
Rising Trojan.Kryptik!1.BE9F (CLASSIC)
SentinelOne DFI – Suspicious PE
Sophos Mal/Generic-S
Symantec Trojan Horse
TrendMicro TROJ_FRS.VSNW1FJ19
TrendMicro-HouseCall TROJ_FRS.VSNW1FJ19
VBA32 TrojanDropper.Agent
VIPRE Trojan.Win32.Generic!BT
ViRobot Trojan.Win32.S.Agent.808448.A
Webroot W32.Trojan.Gen
Zillya Trojan.Chapak.Win32.84672
ZoneAlarm Trojan.Win32.Chapak.ebqm

How to remove Win32/Kryptik.GXTK?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

2 months ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

2 months ago