Malware

Win32/Kryptik.GGFK information

Malware Removal

The Win32/Kryptik.GGFK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGFK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Win32/Kryptik.GGFK?


File Info:

crc32: 536BA26B
md5: 6e4cdfe2365a65c4bc29a9f3a5ee26e1
name: 6E4CDFE2365A65C4BC29A9F3A5EE26E1.mlw
sha1: 253012849f28c9630df36e9afcdfef3479386cbe
sha256: 3a3327c55ea25189de77fac2873ecd5f467ba3e3f64476103dc60ea628d41036
sha512: 6ef7b051a6a5b588555bd7f23fbb016c477f97142b56239cf8c280d6f76133f06c245d8f665113d3db666a998e5278ae53efe304204d959a2e3cde605b663bbd
ssdeep: 3072:di34zy5EGCD+gHFqq5iOS8Znw508gw9gS24JAslRF6WXTJDD11a11A11A11e11wR:di34LG8HFqsw8Zwm8gygSxA+pT7S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, igfpabcew
InternalName: toalatspring.exe
FileVersion: 5.1
ProductVersion: 5.1.111.0
Translation: 0x0789 0x04b1

Win32/Kryptik.GGFK also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.6e4cdfe2365a65c4
CAT-QuickHealTrojan.Cloxer.A06
ALYacTrojan.Ransom.GandCrab.Gen.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforWin.Packed.Gandcrab-6520432-4
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 0056ea8e1 )
Cybereasonmalicious.2365a6
BitDefenderThetaGen:NN.ZexaF.34590.pu1@aa!KLtpi
CyrenW32/S-9659e02a!Eldorado
SymantecPacked.Generic.525
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-5
AvastWin32:Malware-gen
ClamAVWin.Dropper.Gandcrab-6535271-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Gandcrab.b9f1a66c
NANO-AntivirusTrojan.Win32.Mokes.fawxir
ViRobotTrojan.Win32.GandCrab.Gen.A
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoTrojWare.Win32.Magniber.GH@7mr2pk
F-SecureHeuristic.HEUR/AGEN.1102756
ZillyaExploit.CVE.Win32.2127
TrendMicroRansom_GANDCRAB.SMALY-5
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosML/PE-A + Mal/Agent-AUL
IkarusTrojan.Kryptik
JiangminTrojanDownloader.Upatre.ajdp
AviraHEUR/AGEN.1102756
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.Ransom.GandCrab.Gen.2
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
McAfeeTrojan-FPOH!6E4CDFE2365A
TACHYONRansom/W32.GandCrab
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.Generic
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.GGFK
TencentMalware.Win32.Gencirc.10b81df2
YandexTrojan.GenAsa!zGLXM6GZGQI
SentinelOneStatic AI – Malicious PE
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.DQHN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Ransom.GandCrab.HwoCuCMA

How to remove Win32/Kryptik.GGFK?

Win32/Kryptik.GGFK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment