Malware

Win32/Kryptik.GGQG (file analysis)

Malware Removal

The Win32/Kryptik.GGQG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGQG virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system

Related domains:

api-ocean.info

How to determine Win32/Kryptik.GGQG?


File Info:

crc32: 8DB07F0D
md5: 1001173eb86d0cbf757db73ca4cd8ad3
name: 1001173EB86D0CBF757DB73CA4CD8AD3.mlw
sha1: 57a6360f9ceaa47a87f0ca43cd70b56410984dc4
sha256: 1a39de94702c6120747f3e44cb829e8f38771c2525e52e61c15a4b9df9432998
sha512: eed4885582b12e904153a211dddfa3ce0a671efa78b9a68e6239cde0a10cbc0d883d7ae94af50aff5a75d6e7eb433f8ac873c4c5492ac3d29b864449ac128e76
ssdeep: 49152:YfaZYdpjWm/DsPGct4SXaehVwKFnwAT6vcO4zsAQh:rYjjWUoPGct/htwA2vcOJAi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 2.2.0.197
FileVersion: 2.2.0.197
FileDescription: Resource Compiler
Translation: 0x0409 0x04e4

Win32/Kryptik.GGQG also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00537eb21 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3546
CAT-QuickHealTrojan.Ekstak.A02
McAfeePacked-VJ!1001173EB86D
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 00530a3a1 )
Cybereasonmalicious.eb86d0
CyrenW32/FileTour.AT.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GGQG
APEXMalicious
AvastWin32:ICLoader-V [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.FileTour.gen
BitDefenderApplication.Bundler.ICLoader.4.Gen
NANO-AntivirusTrojan.Win32.InstallCube.fbmmhz
MicroWorld-eScanApplication.Bundler.ICLoader.4.Gen
Ad-AwareApplication.Bundler.ICLoader.4.Gen
SophosGeneric PUA FH (PUA)
ComodoApplication.Win32.ICLoader.GS@84429a
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.1001173eb86d0cbf
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2615342
MicrosoftSoftwareBundler:Win32/ICLoader
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataWin32.Adware.ICLoader.D
AhnLab-V3PUP/Win32.ICLoader.R227722
Acronissuspicious
VBA32BScope.Trojan.InstallCube
MAXmalware (ai score=71)
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
YandexTrojan.GenAsa!aFr/SMOtSh0
IkarusPUA.Win32.ICLoader
MaxSecurePacked.Packed.WIN32.Katusha.gen_211973
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-V [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GGQG?

Win32/Kryptik.GGQG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment