Malware

About “Win32/Kryptik.GAAM” infection

Malware Removal

The Win32/Kryptik.GAAM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GAAM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Cerber ransomware
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GAAM?


File Info:

crc32: 8E668057
md5: 88ba864bdfcaa4281b53ee3b54c72aab
name: 88BA864BDFCAA4281B53EE3B54C72AAB.mlw
sha1: 73e2ac28c1cf6912b98da32222bfc59291afb473
sha256: 10c4aa6aeb88bc3da851b75a2363178aa543002233be9eb97464623f7994291d
sha512: 94634b795d7bae36308d23e6dda4b128003cd40f5eaa0a934e6b5606b686d688a9ceaf4686d93c933e75edb71657998f2634cfe9d2e3c41dbb6911bc25abf0de
ssdeep: 6144:20M3L8w+DiGpBYDV8f7uCuQ+193u7WCvbaW3RbE/Qt:e78wHIwVaS1T93QWCGQt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2006 Microsoft Corporation. All rights reserved.
InternalName: dssm
FileVersion: 12.0.6606.1000
CompanyName: Microsoft Corporation
LegalTrademarks1: Microsoftxae is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windowsxae is a registered trademark of Microsoft Corporation.
ProductName: Microsoft Office Document Update Utility
ProductVersion: 12.0.6606.1000
FileDescription: Microsoft Office Document Update Utility
OriginalFilename: dssm.exe
Translation: 0x0000 0x04e4

Win32/Kryptik.GAAM also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.88ba864bdfcaa428
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
SangforMalware
BitDefenderTrojan.Ransom.Cerber.1
Cybereasonmalicious.bdfcaa
CyrenW32/Zbot.JC.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Evo-gen [Susp]
TencentMalware.Win32.Gencirc.10ce0e19
Ad-AwareTrojan.Ransom.Cerber.1
EmsisoftTrojan.Ransom.Cerber.1 (B)
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebTrojan.MulDrop14.3198
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Backdoor.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Boaxxe
JiangminTrojan.Zerber.ejj
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Ransom.Cerber.1
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Cerber.C4223280
Acronissuspicious
McAfeeGenericRXDH-PF!88BA864BDFCA
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesRansom.Cerber
ESET-NOD32a variant of Win32/Kryptik.GAAM
RisingRansom.Petya!8.48D7 (TFE:1:WjHIFbtMbQB)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Kryptik.HCAW!tr
BitDefenderThetaAI:Packer.4FFFD68B1F
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.3FBB.Malware.Gen

How to remove Win32/Kryptik.GAAM?

Win32/Kryptik.GAAM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment