Malware

Win32/Kryptik.GKGP removal guide

Malware Removal

The Win32/Kryptik.GKGP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GKGP virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.GKGP?


File Info:

crc32: 919976DD
md5: 424563a7746a83fb7e913732bd7f5765
name: 424563A7746A83FB7E913732BD7F5765.mlw
sha1: e926362648ae3abafe1a7f10df57bb100c23057d
sha256: de06b17e3df359354342fb82dbc7fa88b98e33a4684f337d342be11fb985fcf2
sha512: c1fb29107259d6719be6ccee242efac752336a02946b109fa6afe2b5451a5dce15fa7f058130e86197b1b026bb1701bf8b74911b2717c526346a10f3a41c9ece
ssdeep: 6144:Bc0h522p3l04ZMSmIp3Uy28uhyI9udwI3H0WVwGWwP+IZ6:Nhxp3lZnT9bD8uqI3HHb6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GKGP also known as:

K7AntiVirusTrojan ( 0053b6dc1 )
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.40427049
CylanceUnsafe
SangforInfostealer.Win32.Coins.a
AlibabaTrojan:Win32/Kryptik.e3804869
K7GWTrojan ( 0053b6dc1 )
Cybereasonmalicious.7746a8
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.GKGP
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:Trojan-PSW.Win32.Coins.a
BitDefenderTrojan.GenericKD.40427049
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKD.40427049
TencentWin32.Trojan.Falsesign.Pabt
Ad-AwareTrojan.GenericKD.40427049
SophosMal/Generic-S
ComodoMalware@#eje0rg9vetl6
BitDefenderThetaGen:NN.ZexaF.34170.luX@a0FS7KcO
VIPRETrojan.Win32.Generic!BT
TrendMicroHEUR_JS.NOOB
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.424563a7746a83fb
EmsisoftTrojan.GenericKD.40427049 (B)
SentinelOneStatic AI – Suspicious SFX
AviraTR/AD.MoksSteal.nelvv
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASMalwS.27DCD00
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.40427049
McAfeeArtemis!424563A7746A
VBA32TScope.Malware-Cryptor.SB
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!UWqAwYBDz2U
IkarusTrojan.Crypt
FortinetW32/GenKryptik.CIGB!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GKGP?

Win32/Kryptik.GKGP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment