Malware

Win32/Kryptik.GCKK (file analysis)

Malware Removal

The Win32/Kryptik.GCKK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GCKK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine Win32/Kryptik.GCKK?


File Info:

crc32: F6FD87C6
md5: f95eb90da477da0666aee20aab35cba3
name: F95EB90DA477DA0666AEE20AAB35CBA3.mlw
sha1: 5ea5ac15adc927e9a5dffd38a4e587e2a550d075
sha256: ad133762eb7fd08d2e6c5e455d33362a2968e2355be9089c6fed21dc09931662
sha512: bf8a1764f84bc5dbbd9f47c322ff31d964ed15e883b8695e1d9ddb0eb983a0e511728c96a32db34e7fad5e4482b2933390894e475c2b245b1b1628a2206cd98d
ssdeep: 3072:N1TwQtGXQF1yc26P/WEvJCTWjdvWgIL1K3aXUcppUUoa0kpFD6Msn:N1TT8QztJCTW5WgIL43aXnAw0qFD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GCKK also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052908c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.BRMon.Gen.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
Alibabavirus:Win32/InfectPE.ali2000007
K7GWTrojan ( 0052908c1 )
Cybereasonmalicious.da477d
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GCKK
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Emotet-6441326-0
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderTrojan.BRMon.Gen.1
NANO-AntivirusTrojan.Win32.Jorik.exhyfv
MicroWorld-eScanTrojan.BRMon.Gen.1
TencentWin32.Trojan.Generic.Ednq
Ad-AwareTrojan.BRMon.Gen.1
SophosML/PE-A + Mal/Ransom-FN
ComodoTrojWare.Win32.Occamy.A@7ijixk
BitDefenderThetaGen:NN.ZexaF.34758.muW@amtWasl
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.f95eb90da477da06
EmsisoftTrojan.BRMon.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.ytu
WebrootW64.Msil.Coinminer
AviraTR/Downloader.Gen7
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.244B236
MicrosoftVirTool:Win32/Obfuscator.CAP
AegisLabTrojan.Win32.GandCrypt.tpiS
GDataTrojan.BRMon.Gen.1
AhnLab-V3Trojan/Win32.Hermesran.R218818
Acronissuspicious
McAfeePacked-YR!F95EB90DA477
MAXmalware (ai score=100)
VBA32Trojan.Encoder
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingTrojan.Generic@ML.100 (RDML:vOpmm8y2+0n18TdG4gbddQ)
YandexTrojan.GenAsa!U+HhvNScvu4
IkarusVirus.Win32.Obfuscator
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CPYR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GCKK?

Win32/Kryptik.GCKK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment