Malware

Win32/Kryptik.OOG removal

Malware Removal

The Win32/Kryptik.OOG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.OOG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.gvt1.com
update.googleapis.com

How to determine Win32/Kryptik.OOG?


File Info:

crc32: 234DD0D4
md5: 070ded4215246f054d8d4dd4f565e818
name: 070DED4215246F054D8D4DD4F565E818.mlw
sha1: d5b5b95b21df4c6bbc8661b0363bdbdf8d09af0e
sha256: e84e2d954314e4bf02b288488e25b24ad5c885ceedf74b746c235e1631dd58fa
sha512: 6eb3fca6a6ee62f728090d3ce24aec1401a28a2fabb8856e2e24f647e0be706691750e796a8165deffcb50de5cee66ad91d0e4e3795d31d118753c6c366a2e41
ssdeep: 1536:+Ofn6TV1XClNDFy5CuAY1X+6KDvV7o1lcscsPQZ9D5t4v6a3hmQJnjfdZoxyYg:38rXoDFQnAYdvKJ7o1lcFpZZsvJFZbL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.OOG also known as:

MicroWorld-eScanGen:Heur.FKP.1
ALYacGen:Heur.FKP.1
CylanceUnsafe
VIPRETrojan.Win32.Ransom.do (v)
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Heur.FKP.1
K7GWTrojan ( 0056ea461 )
K7AntiVirusTrojan ( 0056ea461 )
CyrenW32/Ransom.J.gen!Eldorado
SymantecTrojan.Ransomlock!gen2
APEXMalicious
AvastWin32:Mystic
ClamAVWin.Trojan.Hmblocker-912
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Genasom.c3d66f3e
NANO-AntivirusTrojan.Win32.Kryptik.fbauir
RisingRansom.Genasom!8.293 (CLOUD)
Ad-AwareGen:Heur.FKP.1
EmsisoftGen:Heur.FKP.1 (B)
ComodoMalware@#2ahe0vcxeus2n
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Packed.21756
ZillyaTrojan.HmBlocker.Win32.1291
TrendMicroTROJ_FAKEAV.SMWR
McAfee-GW-EditionFakeAV-SecurityTool.js
FireEyeGeneric.mg.070ded4215246f05
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/HmBlocker.atn
WebrootW32.Trojan.Hmblocker.Gen
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Genasom.DN
ArcabitTrojan.FKP.1
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.FKP.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FakeAV.R5556
McAfeeFakeAV-SecurityTool.js
VBA32Trojan.ExpProc.014
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
ESET-NOD32a variant of Win32/Kryptik.OOG
TrendMicro-HouseCallTROJ_FAKEAV.SMWR
TencentWin32.Trojan.Generic.Crl
YandexTrojan.HmBlocker!NAiXAG3RtL4
IkarusTrojan-Ransom.Timer
MaxSecureTrojan.Yakes.dwnc
FortinetW32/RansomTimer.fam!tr
BitDefenderThetaGen:NN.ZexaF.34590.fq0@aeFeH7ik
AVGWin32:Mystic
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBxicA

How to remove Win32/Kryptik.OOG?

Win32/Kryptik.OOG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment