Malware

Win32/Kryptik.GGYR removal guide

Malware Removal

The Win32/Kryptik.GGYR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGYR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Win32/Kryptik.GGYR?


File Info:

crc32: 5AA76ADF
md5: 4593aa9336a4b800c69cdb7cfe177624
name: 4593AA9336A4B800C69CDB7CFE177624.mlw
sha1: 80396404017461f4e78fcc7f4c11774f498d6f11
sha256: 4f52b0963a325d13e2cef70313a7e5800a84d40c3f2a2f1077e96af50607ccaf
sha512: 9177e94ee5a46d3d0b0f6233431872b0e66da2362aba0e11fd782a11be7889e61fbe725095eaaaaba513cc530e75283c91fb3e46f253012c2b5e1ca3b8129b9c
ssdeep: 3072:kEKOPVdXaXn9WOQVcWvmYyppUS0Bw8eGi8P0fzFDovoDS+YWZnTC7KKMVG7UvqZF:Rn0WVLq6xiFxDoPQC3J7UvzM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GGYR also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.4593aa9336a4b800
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.GandCrab
MalwarebytesRansom.GandCrab
VIPRETrojan.Win32.Generic!BT
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.336a4b
BitDefenderThetaGen:NN.ZexaF.34590.myX@aK77yFm
CyrenW32/S-97c363a1!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Panda.fcluyr
ViRobotTrojan.Win32.GandCrab.Gen.A
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.10b24a6e
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
SophosMal/Generic-R + Mal/GandCrab-D
ComodoTrojWare.Win32.Magniber.FGH@7nyazg
F-SecureHeuristic.HEUR/AGEN.1103309
DrWebTrojan.PWS.Panda.13454
ZillyaDownloader.Quant.Win32.2
TrendMicroRansom.Win32.GANDCRAB.SMLA.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.ajgh
AviraHEUR/AGEN.1103309
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Ransom.GandCrab.Gen.2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
McAfeeGenericRXFN-SN!4593AA9336A4
MAXmalware (ai score=95)
VBA32BScope.Trojan.Encoder
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GGYR
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!2YSnCd5zXMA
IkarusTrojan.Crypt
eGambitUnsafe.AI_Score_81%
FortinetW32/Kryptik.GXCI!tr
MaxSecureRansomeware.GandCrypt.Gen
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Dropper.bb9

How to remove Win32/Kryptik.GGYR?

Win32/Kryptik.GGYR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment