Malware

How to remove “Win32/Kryptik.GGVS”?

Malware Removal

The Win32/Kryptik.GGVS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGVS virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:50000
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
rfisoty.com
marrivate.com

How to determine Win32/Kryptik.GGVS?


File Info:

crc32: 0BF35C28
md5: ba57284022b1b8068d73b24bb2beba78
name: BA57284022B1B8068D73B24BB2BEBA78.mlw
sha1: 3da7c73fca48f46b8218eeebb386f860de80ab3a
sha256: 0004cf672217debfab3fdfc6a25561ff295782aaa4e6df0dcc2f166148e01dbf
sha512: bb8dd0b1e2bcbfd2b229ebd836e097be29589ff65d1ba0e541bf2aeec85c3caddca71d15890f6fdf886f5d1c032e028d1a960861c38d736eda9aea7121568605
ssdeep: 12288:lV+4MI9vSRXVUL1D1MeHwMwMuMTlsVvJMmQ0:H+VSKRlA1D1ZSMrlM+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersion: 7, 1, 8615, 7614
CompanyName: FineDecimal la
LegalTrademarks: Lake Cause
ProductName: Lake Cause
ProductVersion: 7, 1, 8615, 7614
FileDescription: Lake Cause
OriginalFilename: Lake Cause.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.GGVS also known as:

K7AntiVirusTrojan ( 0053a0af1 )
Elasticmalicious (high confidence)
DrWebTrojan.IcedID.12
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.GenericKD.31086758
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.155351
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWTrojan ( 0053a0af1 )
Cybereasonmalicious.022b1b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GGVS
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.31086758
NANO-AntivirusTrojan.Win32.Kryptik.ffbbkl
MicroWorld-eScanTrojan.GenericKD.31086758
TencentMalware.Win32.Gencirc.114cfbfc
Ad-AwareTrojan.GenericKD.31086758
SophosMal/Generic-S
ComodoMalware@#3ir37uva366te
BitDefenderThetaGen:NN.ZexaF.34236.Cq0@a46tUcii
VIPRETrojan.Win32.Zbot.ata (v)
TrendMicroTrojanSpy.Win32.URSNIF.SMKA0.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
FireEyeGeneric.mg.ba57284022b1b806
EmsisoftTrojan.GenericKD.31086758 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.IcedID.ct
AviraHEUR/AGEN.1124574
eGambitUnsafe.AI_Score_81%
Antiy-AVLTrojan/Generic.ASMalwS.26F3F71
MicrosoftTrojan:Win32/Occamy.C00
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.31086758
McAfeeGenericRXGE-DG!BA57284022B1
MAXmalware (ai score=96)
VBA32TrojanBanker.IcedID
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMKA0.hp
RisingTrojan.Generic@ML.100 (RDML:QrZrjD9boQqKdvHhnuHKqA)
YandexTrojan.PWS.IcedID!CuwNVb6DDBE
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.CDUE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GGVS?

Win32/Kryptik.GGVS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment