Malware

Win32/Kryptik.MGG removal

Malware Removal

The Win32/Kryptik.MGG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.MGG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.MGG?


File Info:

name: 469435CCFE11A9911D83.mlw
path: /opt/CAPEv2/storage/binaries/61af1bbc2019388ad4a6c2faeec0b70edcdc500c1093ec3a6f86f345a17d0d6e
crc32: 85510CC7
md5: 469435ccfe11a9911d8354de64d71485
sha1: 1aae6553781f79dee95ead2add7b27c2e52a4fb0
sha256: 61af1bbc2019388ad4a6c2faeec0b70edcdc500c1093ec3a6f86f345a17d0d6e
sha512: 2da6fa09294500258f056dc1f91599ce6e64f4fc7b4ee613c57e094761eb974c85940b585fefb3de02286c55e58d0955aacda9fab2620730b13b315d4e5f179d
ssdeep: 6144:c+ZxaJcxeSL/R0walI1aXbd9DJI1zKjjqtqIAgAfGX/dSSc+B/Cqorx3C65nlOh:9Zdx/LCwalUax9uzSGMxCRVVoVtnl0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A8402CB6382CC2AC5065B78E92AAFBE1142DC5EEDB4BF97C5163E1F31B0A5C9087511
sha3_384: c80998868cf7672cbfbe5f8daeebc2e4d2e054c035cb4b01770650076e2e6c9b52ffbb1dddb4a9f684d944dad2ccc25f
ep_bytes: 558bec81c4dcfaffff566a208d742450
timestamp: 1970-01-01 05:15:07

Version Info:

0: [No Data]

Win32/Kryptik.MGG also known as:

BkavW32.RansomQKC.Fam.Trojan
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Cridex.2
FireEyeGeneric.mg.469435ccfe11a991
CAT-QuickHealFraudTool.Security
SkyhighBehavesLike.Win32.SuspiciousFake.fc
Cylanceunsafe
ZillyaTrojan.FakeAV.Win32.58076
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00234edd1 )
AlibabaVirTool:Win32/Obfuscator.63b36369
K7GWTrojan ( 00234edd1 )
Cybereasonmalicious.cfe11a
BitDefenderThetaGen:NN.ZexaF.36802.wqW@a0u2MRoi
VirITTrojan.Win32.Zyx.X
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.MGG
APEXMalicious
TrendMicro-HouseCallTROJ_FAKEAV.SMID
ClamAVWin.Trojan.Fakeav-38390
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Cridex.2
NANO-AntivirusTrojan.Win32.MLW.dpgei
SUPERAntiSpywareTrojan.Agent/Gen-FakeSecurity
AvastWin32:FakeAV-BLY [Trj]
TencentMalware.Win32.Gencirc.1159c129
TACHYONTrojan/W32.FakeAV.373248.J
EmsisoftGen:Heur.Cridex.2 (B)
F-SecureTrojan.TR/Kazy.17917.26
DrWebTrojan.Fakealert.20577
VIPREGen:Heur.Cridex.2
TrendMicroTROJ_FAKEAV.SMID
Trapminemalicious.high.ml.score
SophosMal/FakeAV-IS
IkarusTrojan.Win32.FakeAV
JiangminTrojan/Fakeav.oxh
VaristW32/FakeAlert.LY.gen!Eldorado
AviraTR/Kazy.17917.26
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.NotVirus.FlashApp.a
MicrosoftRogue:Win32/Winwebsec
XcitiumTrojWare.Win32.FakeAV.BT@338rhv
ArcabitTrojan.Cridex.2
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Cridex.2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R3897
Acronissuspicious
McAfeeGeneric FakeAV.oi
GoogleDetected
MAXmalware (ai score=100)
VBA32BScope.Trojan.FakeAV
MalwarebytesMalware.AI.210595824
PandaTrj/Cycbot.gen
RisingTrojan.FakeAV!1.658F (CLASSIC)
YandexTrojan.GenAsa!jKJbyZdC+is
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/FakeAlert.AMB!tr
AVGWin32:FakeAV-BLY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudSypWare:Win/FlashApp.a

How to remove Win32/Kryptik.MGG?

Win32/Kryptik.MGG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment