Malware

How to remove “Win32/Kryptik.GCGO”?

Malware Removal

The Win32/Kryptik.GCGO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GCGO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Czech
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GCGO?


File Info:

crc32: 401544ED
md5: cc34d4c784f816a56ecb64d14f67996f
name: CC34D4C784F816A56ECB64D14F67996F.mlw
sha1: 5a7ba08c070ea061a3f4600a31245f662f60ac58
sha256: 4cfd00c3fa7b85d2dea3738140fb95c9b52edb55aff73de7dbb92b821656ce11
sha512: 893b650378c90b9585905b585239390f2ad0cac2fdb10255d85c5636d737cce3f2b0ac91234b1c33c1072d3e538d3be2ea6a7d08550b1655e8038026403ed1ce
ssdeep: 6144:cQYZ/SYklXuHjBV56sQInZM3llcw8wSOcOSd1bk7SKGr9gpyh:0VSYk2jBV5FQInZUleOqDEpyh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GCGO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053305e1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.64837
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.BRMon.Gen.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1360372
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Gandcrab.9e6c4b80
K7GWTrojan ( 655333331 )
Cybereasonmalicious.784f81
CyrenW32/S-cab1c03c!Eldorado
SymantecRansom.Crysis
ESET-NOD32a variant of Win32/Kryptik.GCGO
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Emotet-6446128-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.1
NANO-AntivirusTrojan.Win32.Kryptik.exxznb
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
MicroWorld-eScanTrojan.BRMon.Gen.1
TencentMalware.Win32.Gencirc.10c88a41
Ad-AwareTrojan.BRMon.Gen.1
SophosML/PE-A + Mal/Ransom-FN
ComodoApplication.Win32.IStartSurf.PS@8c4m91
BitDefenderThetaGen:NN.ZexaF.34690.tuW@aitK7RcG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMG2
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.cc34d4c784f816a5
EmsisoftTrojan.BRMon.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.wgh
AviraHEUR/AGEN.1126869
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2432958
MicrosoftTrojan:Win32/Gandcrab.GM!MTB
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.BRMon.Gen.1
AhnLab-V3Trojan/Win32.Magniber.R218654
Acronissuspicious
McAfeeGenericRXDW-TY!CC34D4C784F8
MAXmalware (ai score=99)
VBA32Trojan.Scar
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMG2
RisingRansom.Wadhrama!8.E401 (C64:YzY0OpZaQ4bCek27)
YandexTrojan.GenAsa!b1CyoEVYEew
IkarusVirus.Win32.Obfuscator
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GCBO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GCGO?

Win32/Kryptik.GCGO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment