Malware

Win32/Kryptik.GONC (file analysis)

Malware Removal

The Win32/Kryptik.GONC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GONC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
mrbugsbunny.siteme.org

How to determine Win32/Kryptik.GONC?


File Info:

crc32: E6810A6A
md5: d6caa40baae9a3ae00c1f2c033f264c2
name: D6CAA40BAAE9A3AE00C1F2C033F264C2.mlw
sha1: be5651d84dba3195a29af733d360731be5c149ea
sha256: cdce4fc51d62b6bde284a1fd2b65195a46c77a8b8662a13720e836cbac84c941
sha512: 3b307711cf71934fb453b5531292997a72244c6d5b1b7562a1eff2c5b8073726aee2b798c5908706b4258785ab93548cac00d135ba2e832c4796527008f3c63d
ssdeep: 12288:ttj6Crqd5xjHuVNWT2vfz+mt3oO4eVugRDlpdJvLlw9:t96Crqd5xjHuVNWT2vfz+mtYO42ugRDq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Adobe Systems, Incorporated Copyright xa9. 1999 - 2014
InternalName: Discverability
FileVersion: 4.4.52.4
CompanyName: Adobe Systems, Incorporated
FileDescription: Nodetype Straightforward Learners Acre
LegalTrademarks: Adobe Systems, Incorporated Copyright xa9. 1999 - 2014
Comments: Nodetype Straightforward Learners Acre
ProductName: Discverability
Languages: English
ProductVersion: 4.4.52.4
PrivateBuild: 4.4.52.4
OriginalFilename: Discverability
Translation: 0x0409 0x04b0

Win32/Kryptik.GONC also known as:

K7AntiVirusTrojan ( 0053090f1 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Ransom.Ryuk.5
MalwarebytesMachineLearning/Anomalous.100%
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0053090f1 )
Cybereasonmalicious.baae9a
ESET-NOD32a variant of Win32/Kryptik.GONC
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Coins.xi
BitDefenderGen:Variant.Ransom.Ryuk.5
NANO-AntivirusTrojan.Win32.Coins.fbrjxi
MicroWorld-eScanGen:Variant.Ransom.Ryuk.5
TencentWin32.Trojan-qqpass.Qqrob.Wtdq
Ad-AwareGen:Variant.Ransom.Ryuk.5
SophosMal/Generic-S
ComodoMalware@#jaa7omrcfyi9
BitDefenderThetaGen:NN.ZexaF.34126.Du0@a0heI8ei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Expiro.gc
FireEyeGeneric.mg.d6caa40baae9a3ae
EmsisoftGen:Variant.Ransom.Ryuk.5 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137793
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.260CD62
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Ransom.Ryuk.5
AhnLab-V3Malware/Gen.Generic.C2502552
McAfeeGenericRXFU-FK!D6CAA40BAAE9
MAXmalware (ai score=80)
VBA32BScope.TrojanBanker.Gozi
PandaTrj/CI.A
RisingTrojan.Generic@ML.98 (RDML:LG1dl4NiPTutzIqML8/sMQ)
IkarusTrojan-Ransom.GandCrab
FortinetW32/Coins.BZIX!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GONC?

Win32/Kryptik.GONC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment