Malware

Win32/Kryptik.GHHW removal guide

Malware Removal

The Win32/Kryptik.GHHW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GHHW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipv4bot.whatismyipaddress.com
ns1.wowservers.ru
carder.bit
ns2.wowservers.ru
ransomware.bit

How to determine Win32/Kryptik.GHHW?


File Info:

crc32: 43258FC6
md5: 4c514dbb2e081f486deabc6b7a12f7e8
name: 4C514DBB2E081F486DEABC6B7A12F7E8.mlw
sha1: 8bdf2ba7ebab92d62305fdb38c233e786b4851de
sha256: 4f4671081ca762943bf305eedfbec27463782041bf58330f5a4b6eb259ef7e46
sha512: 8431495407747e94b7a2929053fe20b05eca7ed2a494da9f552a8468cff29d067932719870066e2231d981533b065965a7730089a25ed4e54d600dcde6de2cd4
ssdeep: 3072:Klzy1kuowGmdi22wR9m42XLXGSbMlRdCCmUnPnzJlnvOcTUBFGlDdH4isynRBKR:KlmsGx9mNTClRX3nlUfwlZpR8R
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GHHW also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.4c514dbb2e081f48
CAT-QuickHealTrojan.Cloxer.A06
ALYacTrojan.Ransom.GandCrab.Gen.2
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005376c51 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 005376c51 )
Cybereasonmalicious.b2e081
CyrenW32/S-184acebd!Eldorado
SymantecPacked.Generic.525
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.GandCrypt.fdgoff
ViRobotTrojan.Win32.GandCrab.Gen.A
AegisLabTrojan.Win32.GandCrypt.j!c
AvastFileRepMalware
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
ComodoTrojWare.Win32.Magniber.GHYT@7oo2vl
F-SecureHeuristic.HEUR/AGEN.1103299
DrWebTrojan.Encoder.24384
ZillyaTrojan.GandCrypt.Win32.313
TrendMicroRansom.Win32.GANDCRAB.SMLA.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosMal/Generic-R + Mal/Agent-AUL
IkarusTrojan.Win32.Krypt
JiangminTrojanDownloader.Upatre.ajht
AviraHEUR/AGEN.1103299
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt
MicrosoftTrojan:Win32/GandCrypt.PVD!MTB
ArcabitTrojan.Ransom.GandCrab.Gen.2
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
TACHYONRansom/W32.GandCrab
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
McAfeeTrojan-FPRC!4C514DBB2E08
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
CylanceUnsafe
ESET-NOD32a variant of Win32/Kryptik.GHHW
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMLA.hp
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.GenAsa!2Pwpqh7r8eg
SentinelOneStatic AI – Malicious PE
MaxSecureRansomeware.GandCrypt.Gen
FortinetW32/GenKryptik.DWPH!tr
BitDefenderThetaGen:NN.ZexaF.34590.lyX@aCveUzci
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.6cb

How to remove Win32/Kryptik.GHHW?

Win32/Kryptik.GHHW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment