Malware

Win32/Kryptik.GAOA information

Malware Removal

The Win32/Kryptik.GAOA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GAOA virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine Win32/Kryptik.GAOA?


File Info:

crc32: 590354AF
md5: 854ee659a8b5c571984409f0f5417a88
name: 854EE659A8B5C571984409F0F5417A88.mlw
sha1: f57e78302187c32680689ee47b6ca005812bb6f0
sha256: 1a41e5de99c750e353c8ff034be7313708136f61c744fc13c68f91495f906246
sha512: 98d342b718fcf0b79fad50f60c6d9f53adfabde1ef1f721af65864b55b696715cfcecbb5d24062baf427217be5a42d34a25e1c678dc5d1ffc41dea506a9c94ae
ssdeep: 12288:X0Kl6Yz6xjgArC1xO+Fv2qFrcsDwxBcHmc/0H1HaeqQJLX0d3PUKN3:kKl6HjgArCXO+g2ZwxBcHx8HxaeqQJgR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GAOA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005207031 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2610
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Ekstak.A02
ALYacGen:Variant.Adware.ICloader.Symmi.22
CylanceUnsafe
ZillyaAdware.FileTour.Win32.27101
SangforSuspicious.Win32.Save.a
AlibabaAdWare:Win32/FileTour.2b18e955
K7GWTrojan ( 005207031 )
Cybereasonmalicious.9a8b5c
CyrenW32/S-89ac8e8b!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GAOA
APEXMalicious
AvastWin32:AdwareSig [Adw]
Kasperskynot-a-virus:AdWare.Win32.FileTour.hmet
BitDefenderGen:Variant.Adware.ICloader.Symmi.22
NANO-AntivirusRiskware.Win32.FileTour.evzrla
MicroWorld-eScanGen:Variant.Adware.ICloader.Symmi.22
TencentMalware.Win32.Gencirc.10ba855b
Ad-AwareGen:Variant.Adware.ICloader.Symmi.22
SophosGeneric PUA PF (PUA)
ComodoTrojWare.Win32.Crypt.B@7o6bny
McAfee-GW-EditionPacked-OF!854EE659A8B5
FireEyeGeneric.mg.854ee659a8b5c571
EmsisoftApplication.InstallMon (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.FileTour.fta
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.233C7D3
MicrosoftPUADlManager:Win32/InstallCube
ZoneAlarmnot-a-virus:AdWare.Win32.FileTour.hmet
GDataGen:Variant.Adware.ICloader.Symmi.22
AhnLab-V3PUP/Win32.ICLoader.R215747
Acronissuspicious
McAfeePacked-OF!854EE659A8B5
VBA32AdWare.FileTour
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AF4A (CLASSIC)
YandexTrojan.GenAsa!spt7L1p4kxQ
IkarusTrojan-Downloader.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GAOA?

Win32/Kryptik.GAOA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment