Malware

Win32/Kryptik.GAKY (file analysis)

Malware Removal

The Win32/Kryptik.GAKY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GAKY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GAKY?


File Info:

crc32: 6D1C611F
md5: bc56d894e697ababfe849e618df0e51a
name: BC56D894E697ABABFE849E618DF0E51A.mlw
sha1: 7e6aa6d25622b132e0dbaba1899de676d12788ea
sha256: f48362968536232ef1ab1c63b73a6571cbf3865617b297ab72efeed799dd5d51
sha512: 593c4571418c836c7e53485b8e66c60c1e054bf83f34d12be57fb09e4dbef836495143cfb5b25edcc7d6bace5eafba2225c122f52f35369e18113f4e4a9d9cb2
ssdeep: 6144:C/gH5xAVrfavykRBUCitO0rKRbfCHKC/yI5BU7PbyKn6NywrFDS5gFK7rCiKe:xH5xARCRaDtJgKHzqQMuKn6FrFNkXie
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GAKY also known as:

BkavW32.Common.8EC9AB37
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BRMon.Gen.4
FireEyeGeneric.mg.bc56d894e697abab
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.4
MalwarebytesTrojan.MalPack
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderTrojan.BRMon.Gen.4
K7GWTrojan ( 005204461 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34590.FuW@aqfJehC
CyrenW32/S-e64ad02f!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Emotet-6397442-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.4d87c870
NANO-AntivirusTrojan.Win32.Scar.evxugr
ViRobotTrojan.Win32.Ransom.128512.A
AegisLabTrojan.Win32.Scar.4!c
TencentMalware.Win32.Gencirc.10ba9257
Ad-AwareTrojan.BRMon.Gen.4
EmsisoftTrojan.BRMon.Gen.4 (B)
ComodoTrojWare.Win32.Crypt.BP@7j004a
F-SecureHeuristic.HEUR/AGEN.1106533
DrWebTrojan.DownLoad3.49501
ZillyaTrojan.Scar.Win32.107926
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S + Mal/GandCrab-D
IkarusTrojan.Win32.Crypt
JiangminTrojan.Matrix.bg
MaxSecureRansomeware.GandCrypt.Gen
AviraHEUR/AGEN.1106533
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.BRMon.Gen.4
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.N
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/MalPe34.Suspicious.X2029
Acronissuspicious
McAfeeEmotet-FAX!
MAXmalware (ai score=99)
VBA32Trojan.Inject
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GAKY
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingMalware.Obscure/Heur!1.A89E (CLOUD)
YandexTrojan.Scar!qVgktcdwLQ8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.GASG!tr.ransom
WebrootW32.Trojan.Emotet
AVGFileRepMalware
Cybereasonmalicious.4e697a
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCAwcA

How to remove Win32/Kryptik.GAKY?

Win32/Kryptik.GAKY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment