Malware

Win32/Kryptik.GCAW malicious file

Malware Removal

The Win32/Kryptik.GCAW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GCAW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Czech
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com
www.adobe.com

How to determine Win32/Kryptik.GCAW?


File Info:

crc32: 13F9C919
md5: 793f2716fa4366d937cb23cc6c6ddec7
name: 793F2716FA4366D937CB23CC6C6DDEC7.mlw
sha1: a17de2c5f14444db8c170fe24781d67adbd01866
sha256: 420cc08e120b0f7b6e88de9845594abdaa68e5bab0a11dbb456ec3f2245b5042
sha512: 2614f66db0d1b4b93af649ce1c800d3aaf5db08999cb1d274ae5b8573046a04514aeb123b0ed38ae27282e48c367fc09a32aae5da4255553d315de585f2de515
ssdeep: 6144:nh6EEmmKi+ghW8ZZckWw/g5jdpHaL/AQ+IsDu1bO3:nh6ZKir9ZakWw/g55p6LZdO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GCAW also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BRMon.Gen.1
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXDX-OW!793F2716FA43
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.6fa436
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GCAW
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
ViRobotTrojan.Win32.Ransom.229376.C
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
Ad-AwareTrojan.BRMon.Gen.1
ComodoTrojWare.Win32.Crypt.BV@7i8vhf
BitDefenderThetaGen:NN.ZexaF.34770.nuW@aCJ9XYoG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
FireEyeGeneric.mg.793f2716fa4366d9
SophosMal/Generic-S + Mal/Ransom-FN
SentinelOneStatic AI – Malicious PE
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1121558
eGambitUnsafe.AI_Score_99%
AegisLabTrojan.Win32.Yakes.4!c
MicrosoftVirTool:Win32/Obfuscator.CAP
AhnLab-V3Trojan/Win32.Matrixran.R218216
Acronissuspicious
MAXmalware (ai score=96)
MalwarebytesMalware.AI.4073029830
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
TencentMalware.Win32.Gencirc.11491bff
YandexTrojan.GenAsa!+S8TD/oBk2E
IkarusVirus.Win32.Obfuscator
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GCBO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwoCuFcA

How to remove Win32/Kryptik.GCAW?

Win32/Kryptik.GCAW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment