Malware

Win32/Kryptik.GCCA removal instruction

Malware Removal

The Win32/Kryptik.GCCA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GCCA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GCCA?


File Info:

crc32: 3C5A0B7B
md5: f806baea99bacfbe364e07c58951d225
name: F806BAEA99BACFBE364E07C58951D225.mlw
sha1: d20e45da67bcf2e35bb005a6d5f30a5cbf18d5e1
sha256: 7875a86f6d5f2f50de7f39b078d226d0d957cd71b8d676071cca356152503152
sha512: 666f8582530e67cda05fc174175317439df5a2f2cef808c0b38a0da639a682edad2e26e471c686d3ad9df3c9c7ec40f6442806249854cddfd0739a79842d28f5
ssdeep: 3072:IfhU+wCGxtX5So++2qUbyDOcNMhL4IfUXUUB7K0E+Pw3NSc0Zt/7NkbgpEHz7uJ:T75+bDbR4IfUNK33sc0ZtAiwTf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GCCA also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BRMon.Gen.4
FireEyeGeneric.mg.f806baea99bacfbe
Qihoo-360Win32/Ransom.CrySiS.HgIASOQA
ALYacTrojan.BRMon.Gen.4
CylanceUnsafe
AegisLabTrojan.Win32.Crusis.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056f40a1 )
AlibabaRansom:Win32/Crusis.2f1958cc
K7GWTrojan ( 0056f40a1 )
Cybereasonmalicious.a99bac
BitDefenderThetaGen:NN.ZexaF.34608.ruW@a4ln0Rai
SymantecPacked.Generic.525
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Crusis.btb
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Crusis.ewflel
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Malware-gen
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
Ad-AwareTrojan.BRMon.Gen.4
EmsisoftTrojan.BRMon.Gen.4 (B)
ComodoMalware@#22cc3mfvf4blu
F-SecureHeuristic.HEUR/AGEN.1102650
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataTrojan.BRMon.Gen.4
JiangminTrojan.Crusis.qv
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1102650
MAXmalware (ai score=94)
Antiy-AVLTrojan/Win32.TSGeneric
GridinsoftRansom.Win32.Gandcrab.sa
ArcabitTrojan.BRMon.Gen.4
ZoneAlarmTrojan-Ransom.Win32.Crusis.btb
MicrosoftRansom:Win32/CerberCrypt.SU!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R216014
Acronissuspicious
McAfeeGenericRXEU-QV!F806BAEA99BA
TACHYONRansom/W32.Crysis.283648
VBA32BScope.Trojan.Download
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Kryptik.GCCA
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
TencentWin32.Trojan.Crusis.Ebgg
YandexTrojan.GenAsa!XDlD+UFRbmg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GASG!tr.ransom
AVGWin32:Malware-gen
PandaTrj/RnkBend.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureRansomeware.GandCrypt.Gen

How to remove Win32/Kryptik.GCCA?

Win32/Kryptik.GCCA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment