Malware

How to remove “Win32/Kryptik.GYTS”?

Malware Removal

The Win32/Kryptik.GYTS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Kryptik.GYTS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GYTS?


File Info:

crc32: D9F01318
md5: 87a0dbc15288ddc57558f5fd3a1a2513
name: asdfg.exe
sha1: ac9ee612b29b94761c7dc284e5bcab14561c03a6
sha256: 1d8fe1ee69caa87ae8b987a3f6c443916e65a8e413820584fbdd4140365bc4dc
sha512: 459c55dbbadd5a91669044d079cf8847bb408f18c05aea35c494497293561a2afee3d0eca2da7604e2dc57e367ef98c825645f984de271c5d0218a101d98d3cc
ssdeep: 6144:1uWieVaCDFrNAiJ1M3Bzbh8AAsyOMi8lVS8/5:1VlaAv16/8ASOcn
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) tonsillectomic 2019
InternalName: maniere.exe
FileVersion: 6.5.8.2
CompanyName: propagula
ProductName: acrostolium
ProductVersion: 1.4.2.6
FileDescription: glochidia
OriginalFilename: challas.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GYTS also known as:

FireEyeGeneric.mg.87a0dbc15288ddc5
CylanceUnsafe
BitDefenderThetaGen:NN.ZexaF.32515.ny3@a82V4Cgi
APEXMalicious
Invinceaheuristic
SentinelOneDFI – Malicious PE
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Wacatac.B!ml
ESET-NOD32a variant of Win32/Kryptik.GYTS
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Kryptik.GYTS?

Win32/Kryptik.GYTS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment