Malware

Win32/Kryptik.GYYF removal tips

Malware Removal

The Win32/Kryptik.GYYF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GYYF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Looks up the external IP address
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

advertspace10.club
logstat17.club
api.ipify.org

How to determine Win32/Kryptik.GYYF?


File Info:

crc32: C4A01634
md5: 1b557961df2810b8026bae3205317fe8
name: ztx777.exe
sha1: aa4e931a7ddcd18eebc72b8422ad225e5b2b0d74
sha256: 2da83a63d58019a926c3c2f5288da2e999c602548c6112cd1c67e9e15e357d83
sha512: 505066eda6df33ce7d8deed5c31ae0014e8a1d886949468260451e66c5a9c6403c9a15cc0224276dfd923fa43d659c198726a48d143bbc8a4ca4653b69202cd3
ssdeep: 3072:+6NpTMXAACeZFUblrJQt23SoyLciHc5/1KIO0G0a3W/dCj:hlMXNTUblVQtbL585NGTW/gj
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Canneverbe Limited (C)
InternalName: Negotiating
CompanyName: Canneverbe Limited
ProductName: Negotiating
ProductVersion: 1.8.9.863
FileDescription: Leonards Cnditiner Wrkitemlinkfilters
Translation: 0x0409 0x04b0

Win32/Kryptik.GYYF also known as:

McAfeeRDN/Generic.dx
CylanceUnsafe
SangforMalware
Cybereasonmalicious.a7ddcd
TrendMicroMal_HPGen-37b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GYYF
APEXMalicious
KasperskyTrojan-Proxy.Win32.Sybici.gm
BitDefenderTrojan.GenericKD.42072583
RisingTrojan.Generic@ML.86 (RDML:wUcb35U5Qm4m/64iX8/TEQ)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.ZvuZona.dc
FortinetW32/Malicious_Behavior.VEX
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.1b557961df2810b8
IkarusTrojan-Ransom.GandCrab
WebrootW32.Trojan.Gen
Endgamemalicious (moderate confidence)
ZoneAlarmTrojan-Proxy.Win32.Sybici.gm
MicrosoftTrojan:Win32/Zpevdo.A
AhnLab-V3Trojan/Win32.Download.C3604742
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallMal_HPGen-37b
SentinelOneDFI – Suspicious PE
BitDefenderThetaGen:NN.ZexaF.32515.nmKfau2cGQii
AVGFileRepMetagen [Malware]
AvastFileRepMetagen [Malware]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Proxy.433

How to remove Win32/Kryptik.GYYF?

Win32/Kryptik.GYYF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment