Malware

Win32/Kryptik.GGKS removal instruction

Malware Removal

The Win32/Kryptik.GGKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGKS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Removes Security and Maintenance icon from Start menu, Taskbar and notifications
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify user notification settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.GGKS?


File Info:

name: 803EE6B3FA7EB76FFA15.mlw
path: /opt/CAPEv2/storage/binaries/c682e18d8568ebecb63e2bac7b3c9048867a6a4e4310b783fb2fbcb0dee19956
crc32: 66AB4243
md5: 803ee6b3fa7eb76ffa152a51373b49f2
sha1: 0b3c3ff5d0f3722f7d545d67292e789d6deb1453
sha256: c682e18d8568ebecb63e2bac7b3c9048867a6a4e4310b783fb2fbcb0dee19956
sha512: 1792229b34c6740f46717305861d5f4f3edea6d9e2716b8b3430c6036d9643c6d6b26164b69a39d9ef03b3ea0876bca901874c8f0b9c89b3d37ee80ce60235bb
ssdeep: 12288:BVdlPT//2mFDTWAIYkKkVeTwMiatl8hcx/:dlTn/DTUYaVFMiavx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DFA41229B500C2B9D49474F44FA9901BA4A86C5041E169E31BF8FE5BBD711BBCDA32FC
sha3_384: 8db4a125c2df126392d3a031cf0c1f091d216ffb38b9bbc335999632725e313ff5de295225879ef62a13d761ba1a14bc
ep_bytes: 6a606878814100e89c140000bf940000
timestamp: 2012-04-25 18:40:08

Version Info:

0: [No Data]

Win32/Kryptik.GGKS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.SmartFortress2012.lx3p
tehtrisGeneric.Malware
DrWebTrojan.Siggen20.5979
MicroWorld-eScanGen:Trojan.Brresmon.Gen.1
CAT-QuickHealFraudTool.Security
SkyhighBehavesLike.Win32.Generic.gc
McAfeeFakeAV-SecurityTool.eg
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.197023
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirTool:Win32/Katusha.aeef873c
K7GWTrojan ( 00547e9f1 )
K7AntiVirusTrojan ( 00547e9f1 )
ArcabitTrojan.Brresmon.Gen.1
BitDefenderThetaGen:NN.ZexaF.36680.DqW@aqiB5Cfi
VirITTrojan.Win32.FakeAV_r.DS
SymantecTrojan.FakeAV!gen89
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GGKS
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Fakeav-1723
KasperskyHEUR:Trojan.Win32.FakeAV.gen
BitDefenderGen:Trojan.Brresmon.Gen.1
NANO-AntivirusTrojan.Win32.Kryptik.nprqn
AvastWin32:Katusha-FJ [Trj]
TencentTrojan.Win32.FakeAV.ac
EmsisoftGen:Trojan.Brresmon.Gen.1 (B)
F-SecureTrojan.TR/Winwebsec.azwean
VIPREGen:Trojan.Brresmon.Gen.1
TrendMicroTROJ_FAKEAV.SM66
SophosMal/EncPk-AIA
IkarusTrojan.Win32.FakeAV
JiangminTrojan/SmartFortress2012.aqm
WebrootTrojan.Sirefef.Gen
VaristW32/FakeAlert.TW.gen!Eldorado
AviraTR/Winwebsec.azwean
Antiy-AVLTrojan[FakeAV]/Win32.SmartFortress2012
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AESB@4obfhl
MicrosoftVirTool:Win32/Obfuscator.AFQ
ViRobotTrojan.Win32.A.SmartFortress2012.479232
ZoneAlarmHEUR:Trojan.Win32.FakeAV.gen
GDataGen:Trojan.Brresmon.Gen.1
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R23986
VBA32BScope.Trojan.Ymacco
ALYacGen:Trojan.Brresmon.Gen.1
TACHYONTrojan/W32.Agent.479232.NS
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Resdec.c
TrendMicro-HouseCallTROJ_FAKEAV.SM66
RisingRogue.Winwebsec!8.B21 (TFE:5:CmAYsRNzokB)
YandexTrojan.GenAsa!cAY/BJNchQY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.SmartFortress.B
FortinetW32/Kryptik.GQEQ!tr
AVGWin32:Katusha-FJ [Trj]
Cybereasonmalicious.5d0f37
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.GGKS?

Win32/Kryptik.GGKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment