Threat Database Trojans Trojan.Kryptik.BFITI

Trojan.Kryptik.BFITI

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 424
First Seen: August 1, 2023
Last Seen: December 29, 2025
OS(es) Affected: Windows

The detection of Trojan.Kryptik.BFITI on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. In this report, we will provide you with an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Kryptik.BFITI?

Trojan.Kryptik.BFITI is a type of Trojan horse malware that can infiltrate your system without your knowledge or consent. The name "Trojan" refers to the malware's ability to disguise itself as a legitimate program or file, allowing it to bypass security measures and gain access to your system. The term "Kryptik" suggests that this malware may have encryption or stealth capabilities, making it difficult to detect and remove.

How Trojan.Kryptik.BFITI Operates

Trojan.Kryptik.BFITI, like other Trojans, operates by exploiting vulnerabilities in your system or tricking you into installing it. Once inside, it can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or providing unauthorized access to your system. The malware may also communicate with its creators or other infected systems to receive updates or transmit stolen data.

Trojans often rely on social engineering tactics, such as phishing or fake software updates, to infect systems. They can also spread through infected software downloads, compromised websites, or infected USB drives. The malware may use various techniques to evade detection, including code obfuscation, anti-debugging methods, or rootkit functionality.

Symptoms of Infection

Systems infected with Trojan.Kryptik.BFITI may exhibit a range of symptoms, including slow performance, frequent crashes, or unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups or alerts. In some cases, the malware may not display any noticeable symptoms, making it difficult to detect without the aid of security software.

  • Unexplained changes to your system settings or configuration
  • New or unfamiliar programs or toolbars installed on your system
  • Increased network activity or unusual data transfers
  • Frequent system crashes or errors
  • Slow system performance or responsiveness

How to Remove Trojan.Kryptik.BFITI

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

The removal of Trojan.Kryptik.BFITI requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can help to ensure the complete removal of the malware and prevent future infections. It is essential to remain vigilant and to maintain up-to-date security software to protect your system from the ever-evolving threat landscape. Remember to always be cautious when downloading software or clicking on links, and to never provide sensitive information to unfamiliar or untrusted sources.

Analysis Report

General information

Family Name: Trojan.Kryptik.BFITI
Signature status: No Signature

Known Samples

MD5: 5d92b70d803368f6525f53a555a063cf
SHA1: 41d902a95e671510ecd5aa5c3694b85ab9e03193
SHA256: 0424F91ACE3FD817B16CE0A786AAE44DEF8977B9C0A9179BF9022D1D27B8CF27
File Size: 510.98 KB, 510976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Silly
File Descriptions PlasticFantastic
File Version 13.78.85.48
Internal Name GrowTrees.exe
Legal Copyrights Challangers kenia
Product Name Game
Product Version 4.80.40.45

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 358
Potentially Malicious Blocks: 11
Whitelisted Blocks: 347
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 1 1 1 1 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 2 2 0 0 0 1 0 0 0 0 1 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 2 1 1 3 0 1 1 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 2 3 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 1 0 0 0 0 0 1 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 0 0 1 0 0 0 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\223de96ee265046957a660ed7c9dd9e7_eff9b9ba98deaa773f261fa85a0b1771 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\26c212d9399727259664bdfca073966e_b7ed31d77d311a56fdcb56a0083b3e0b Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\56bd22aed931573ff211080ea231f008_7156f4d84718d1fcbecb4d5e58bee9cd Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\223de96ee265046957a660ed7c9dd9e7_eff9b9ba98deaa773f261fa85a0b1771 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\26c212d9399727259664bdfca073966e_b7ed31d77d311a56fdcb56a0083b3e0b Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\56bd22aed931573ff211080ea231f008_7156f4d84718d1fcbecb4d5e58bee9cd Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...