Malware

Win32/Kryptik.GZKS malicious file

Malware Removal

The Win32/Kryptik.GZKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GZKS virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GZKS?


File Info:

crc32: DB884314
md5: 0fab7f5d3a7c6db3f84ed5674ba0b330
name: socks111atx.exe
sha1: 6ad2bccd7c721d538863e176964f2e0f5938d08a
sha256: f1616ff07c960a4ba01022b8ac00d55129431b0d6aa2b51b35b4a0f6b609f720
sha512: cba525eb35ce33ca63a1d909ba676e30824d6ba1ae3db6af1e2b588b223c862dd450de1cfc30f88273d279ae81ff0fbb845b30f4a0d3e8a308067cbc975a69a5
ssdeep: 6144:BHH7ST57hUydLFRaxL1rmuMaid28FNFuupdM0jEvA:RuThL9FRSrmu6XNFZpd9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0119 0x04e4

Win32/Kryptik.GZKS also known as:

MicroWorld-eScanTrojan.GenericKD.42111029
FireEyeGeneric.mg.0fab7f5d3a7c6db3
McAfeeRDN/Generic.grp
ALYacTrojan.GenericKD.42111029
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0055d55a1 )
BitDefenderTrojan.GenericKD.42111029
K7GWTrojan ( 0055d55a1 )
Cybereasonmalicious.d7c721
BitDefenderThetaGen:NN.ZexaF.33550.vy0@auWHa5nG
F-ProtW32/Agent.BKR.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PLF19
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Generic-7451332-0
GDataTrojan.GenericKD.42111029
KasperskyBackdoor.Win32.Mokes.ahnd
NANO-AntivirusTrojan.Win32.Kryptik.glgpkh
ViRobotTrojan.Win32.Z.Wacatac.353280.C
RisingTrojan.Generic@ML.100 (RDML:aU9BkSSsVxpGm+EEERcsSw)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.MalwareCrypter.lvmqu
DrWebTrojan.Siggen8.63046
McAfee-GW-EditionRDN/Generic.grp
SentinelOneDFI – Malicious PE
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.Crypt (A)
APEXMalicious
CyrenW32/Agent.BKR.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/AD.MalwareCrypter.lvmqu
ArcabitTrojan.Generic.D2829035
ZoneAlarmBackdoor.Win32.Mokes.ahnd
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.MalPe.R303644
Acronissuspicious
VBA32BScope.Trojan.AET.281105
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKD.42111029
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GZKS
IkarusTrojan.Win32.Crypt
FortinetW32/Malicious_Behavior.VEX
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360HEUR/QVM10.2.DA13.Malware.Gen

How to remove Win32/Kryptik.GZKS?

Win32/Kryptik.GZKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment