Malware

Should I remove “Win32/Kryptik.GZWO”?

Malware Removal

The Win32/Kryptik.GZWO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GZWO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

fanblog79.xyz
gameblog18.xyz
api.ipify.org

How to determine Win32/Kryptik.GZWO?


File Info:

crc32: BB710B5E
md5: 1d96698d9b8f1f963e24f636b880c2b7
name: ztx777.exe
sha1: f7d30b2cc07a87314470f098c2569f14b7f1c8cb
sha256: 6b8ef37c55208a9536cd6a054051edf07b2d858295f3f46b9fb01b983c431659
sha512: f3b5105e681a1aa6dbb0f6b1fd41bcd4a33037f6447255b30f0534b1fe14d819d918d25fdb448b73729cae8134226f376f4da63f4f01281a6e210be031793daa
ssdeep: 12288:8qfK8Rc0Z/HUHI0bSRnc+7QSZUWS6dr3z02q3oBXb:8EKu+zUndxZPX0HoBXb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9. 1999 - 2014
InternalName: Kflex
FileVersion: 3.6.92.9
CompanyName: G&G Software
PrivateBuild: 3.6.92.9
ProductName: Kflex
ProductVersion: 3.6.92.9
FileDescription: Revert Symbian Terrr Table Collisions
OriginalFilename: Kflex.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GZWO also known as:

DrWebTrojan.MulDrop11.31868
MicroWorld-eScanTrojan.GenericKD.42190430
FireEyeGeneric.mg.1d96698d9b8f1f96
CAT-QuickHealTrojan.Sybici
Qihoo-360Win32/Trojan.Proxy.f75
McAfeeArtemis!1D96698D9B8F
MalwarebytesTrojan.ProxyAgent
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Sybici.h!c
SangforMalware
K7AntiVirusTrojan ( 0055e04f1 )
BitDefenderTrojan.GenericKD.42190430
K7GWTrojan ( 0055e04f1 )
Cybereasonmalicious.cc07a8
BitDefenderThetaGen:NN.ZexaF.33558.Bu0@aa2!nTii
CyrenW32/Trojan.YLDZ-8929
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42190430
KasperskyTrojan-Proxy.Win32.Sybici.ja
RisingTrojan.Generic@ML.96 (RDML:USQVFpI3sAeb4Lr3bVDd6g)
Ad-AwareTrojan.GenericKD.42190430
EmsisoftTrojan.GenericKD.42190430 (B)
Invinceaheuristic
SophosMal/Generic-S
JiangminTrojanProxy.Sybici.az
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D283C65E
ZoneAlarmTrojan-Proxy.Win32.Sybici.ja
MicrosoftTrojan:Win32/Detplock
Acronissuspicious
ALYacTrojan.GenericKD.42190430
MAXmalware (ai score=99)
VBA32TrojanProxy.Sybici
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.GZWO
FortinetW32/Kryptik.GVSM!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.74755230.susgen

How to remove Win32/Kryptik.GZWO?

Win32/Kryptik.GZWO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment