Malware

Win32/Kryptik.GGAO removal

Malware Removal

The Win32/Kryptik.GGAO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGAO virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GGAO?


File Info:

crc32: 050A1728
md5: de1db083a4c1900cd31921fd50f8c541
name: DE1DB083A4C1900CD31921FD50F8C541.mlw
sha1: 8e26560b5a302d650edb2a50a69cc11a239161df
sha256: 24ae34baf0c884b566f9aabfc75ccb3bc8b80bfae947d3d9812eae81ebe7c694
sha512: 1ab6f6786b961db95cc452fd992da97e6d6e9cfc7c822848d5901728c83521bf05635696de49d16762bb1b11add597005816d37b1858b518b2836329e2d05dd7
ssdeep: 24576:FNvjBNwVoh09e36CHiFu5HCMSEM18EfznZZuWhBec7vPcfuuSX2:zv0Ch0s3lHZJCzEM1nznTzBec7vEfO2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 11.00.15063.0
InternalName: Wextract
FileVersion: 11.00.15063.0 (WinBuild.160101.0800)
OriginalFilename: WEXTRACT.EXE .MUI
FileDescription: Win32 Cabinet Self-Extractor
Translation: 0x0409 0x04b0

Win32/Kryptik.GGAO also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052ee991 )
Elasticmalicious (high confidence)
DrWebTrojan.Moneyinst.550
CAT-QuickHealTrojan.Ekstak.A02
ALYacMemScan:Adware.ICLoader.BN
MalwarebytesAdware.FileTour
ZillyaTrojan.Kryptik.Win32.3044689
K7GWTrojan ( 0052ee991 )
Cybereasonmalicious.3a4c19
CyrenW32/Trojan.BKW.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GGAO
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Packed.Win32.Katusha.gen
BitDefenderMemScan:Adware.ICLoader.BN
NANO-AntivirusTrojan.Win32.Moneyinst.fapzfp
MicroWorld-eScanMemScan:Adware.ICLoader.BN
TencentMalware.Win32.Gencirc.10b3e16a
Ad-AwareMemScan:Adware.ICLoader.BN
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.B@8hjrzn
BitDefenderThetaGen:NN.ZexaF.34266.Pz1@ayrtXwai
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.de1db083a4c1900c
EmsisoftApplication.FileTour (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.hmy
AviraTR/Crypt.ZPACK.Gen
MicrosoftSoftwareBundler:Win32/ICLoader
ArcabitAdware.ICLoader.BN
GDataWin32.Adware.ICLoader.D
AhnLab-V3PUP/Win32.ICLoader.R226539
Acronissuspicious
McAfeePacked-VJ!DE1DB083A4C1
MAXmalware (ai score=99)
VBA32BScope.Trojan.Ekstak
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!r8HKNKyizF0
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GGAO?

Win32/Kryptik.GGAO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment