Malware

Win32/Kryptik.GEOG (file analysis)

Malware Removal

The Win32/Kryptik.GEOG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GEOG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GEOG?


File Info:

crc32: F22606B8
md5: 081c6d2e5054987441fd1e30535483fd
name: 081C6D2E5054987441FD1E30535483FD.mlw
sha1: e949ce5cbc0481c778a81fd28781890294fd551b
sha256: 1e5c7900bdda6f495a8eaabcfcac4477543a5cbca5af9041a28b8f9497aa012e
sha512: 0e02888d815c35ba1712140a393f033d143c38b9c3b47e349060f63515737bd943fb901ac867781e7395d1e06797ca4f3fc265060e1235dae87d3b9db80cf2ae
ssdeep: 98304:8ZzJiNAq2IawnpnoA/Yw285oUq3uT4BP:iUWqUwndxv5oUqS8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Ouhahutduara sudoispanyrane assanarahi
InternalName: NAOBATA.EXE
FileVersion: 3.2.9.6
CompanyName: xa9Ouhahutduara sudoispanyrane assanarahi
ProductName: NAOBATA
ProductVersion: 3.2.9.6
OriginalFilename: naobata.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.GEOG also known as:

K7AntiVirusTrojan ( 005375761 )
LionicAdware.Win32.AdLoad.2!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.779
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Occamy.A2
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.AdLoad.Win32.24764
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/AdLoad.2b8c537e
K7GWTrojan ( 005375761 )
Cybereasonmalicious.e50549
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GEOG
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:AdWare.Win32.AdLoad.addmp
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusRiskware.Win32.AdLoad.ezapdm
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10c8e9e8
Ad-AwareGen:Heur.Mint.Zamg.1
SophosGeneric PUA OJ (PUA)
ComodoApplicUnwnt@#15l0ysj020nvq
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaGen:NN.ZexaF.34266.@t0@aKWyzcji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.tm
FireEyeGeneric.mg.081c6d2e50549874
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdware.Adload.hhm
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Occamy.C1E
ArcabitTrojan.Mint.Zamg.1
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Malware/Win32.Generic.C2441804
Acronissuspicious
McAfeePUP-XEM-DY
MAXmalware (ai score=99)
VBA32Adware.AdLoad
MalwarebytesAdware.DLAssistant
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.86 (RDML:UdwVZrhkXDUcfjMfhbKpUQ)
YandexPUA.AdLoad!t+WEXjtrsrY
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GEIF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GEOG?

Win32/Kryptik.GEOG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment