Malware

Win32/Kryptik.GGFU removal tips

Malware Removal

The Win32/Kryptik.GGFU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGFU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GGFU?


File Info:

crc32: 0A0262F4
md5: 96b8990c47d25bf3d1f1cd79994b009f
name: 96B8990C47D25BF3D1F1CD79994B009F.mlw
sha1: bbc5a98ecb0656690c7cbdd27053e58436bc399c
sha256: 1e0808e3ac6ca20181f43e389cd85c4b9a8a88b7cb32c5c888f3d0750358762e
sha512: c8611ca90126ec4ed22629da943eecea8ea3d90debe55dec77ce221f28ac1d06051eacf708068591bdcfb972323d53854b32834bf7be6e3455f1ee4c1a9474e5
ssdeep: 6144:URxEEKV29rtMuaD/LaHrtpoShl+bPYjtaZqOUW7+Ezi022v1ZBTyLT233q7UmTl:UB9sLQwShoscPJewtZ9yW330KZNR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)Qihu 360 Software Co., Ltd. All rights reserved.
InternalName: 360TSLiveUpd.exe
FileVersion: 9,0,0,1000
CompanyName: QIHU 360 SOFTWARE CO. LIMITED
ProductName: 360 Total Security
ProductVersion: 9,0,0,1000
FileDescription: 360 ipdate Module
OriginalFilename: TSLiveUpd.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GGFU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052f4861 )
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.52159
CynetMalicious (score: 100)
ALYacTrojan.Mint.Zamg.O
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.68449
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0052f4861 )
Cybereasonmalicious.c47d25
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.GGFU
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Cype-7077783-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Mint.Zamg.O
NANO-AntivirusTrojan.Win32.Bunitu.fawtsk
MicroWorld-eScanTrojan.Mint.Zamg.O
TencentMalware.Win32.Gencirc.10ba591d
Ad-AwareTrojan.Mint.Zamg.O
SophosMal/Generic-S
ComodoTrojWare.Win32.Yakes.FN@7ngy6d
F-SecureHeuristic.HEUR/AGEN.1109183
BitDefenderThetaGen:NN.ZexaF.34266.Mq0@a8xcFJbi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.TRICKBOT.SMB.hp
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jh
FireEyeGeneric.mg.96b8990c47d25bf3
EmsisoftTrojan.Mint.Zamg.O (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.zou
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1109183
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.25F4E95
MicrosoftTrojanDropper:Win32/Bunitu.G
GDataTrojan.Mint.Zamg.O
AhnLab-V3Malware/Win32.Generic.R249169
Acronissuspicious
McAfeePacked-FEE!96B8990C47D2
MAXmalware (ai score=97)
VBA32BScope.Trojan.Yakes
MalwarebytesMalware.AI.4031647231
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMB.hp
RisingRansom.Locky!1.AE2E (CLASSIC)
YandexTrojan.Yakes!gnMi8NSADT4
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.GWSH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GGFU?

Win32/Kryptik.GGFU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment