Malware

Should I remove “Win32/Kryptik.GADF”?

Malware Removal

The Win32/Kryptik.GADF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GADF virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GADF?


File Info:

crc32: 930B2D63
md5: bbe9ce447eeae0b62d8733116b2baab0
name: BBE9CE447EEAE0B62D8733116B2BAAB0.mlw
sha1: d349b3019526906bd2faa12a51e0564d725a2f3c
sha256: c80c6aadfb10d7c4570c0f91d839ac373d3e14bf0541f32a9b12970d21cbe648
sha512: acb43d0f6343d102c645351337e693f302ae59f62bf6c6ed343276ed7b263b28ac57ad8f6cadb760d6a3147630c302e77908c729eac18117879e6f2edc0a14ab
ssdeep: 3072:u0Kea52wrFFM+w7tEozClpMKdACjyR16xY1vPKwTs:hKPZFctQlvAmqqw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2008-2011 x41ex41ex41e x42fx43dx434x435x43ax441
InternalName: Punto Switcher Unloader
FileVersion: 3.2.3.51
CompanyName: x41e x41ex41e x42fx43dx434x435x43ax441
LegalTrademarks: Punto Switcher
Comments: x412x44bx433x440x443x437x447x438x43a Punto Switcher
ProductName: Punto Switcher
ProductVersion: 3.2.3.51
FileDescription: x412x44bx433x440x443x437x447x438x43a Punto Switcher
OriginalFilename: puntounloader.exe
Translation: 0x0419 0x04b0

Win32/Kryptik.GADF also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.bbe9ce447eeae0b6
CAT-QuickHealTrojanRansom.Crowti.MUE.A4
McAfeePacked-MU!BBE9CE447EEA
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005224381 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 005224381 )
Cybereasonmalicious.47eeae
BitDefenderThetaGen:NN.ZexaF.34590.pq0@aWFYkDek
CyrenW32/Zbot.JC.gen!Eldorado
SymantecPacked.Generic.459
BaiduWin32.Trojan.Kryptik.ayf
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-6931819-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Cerber.116a8bbb
NANO-AntivirusTrojan.Win32.Kryptik.evriym
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Generic.Pjxh
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Ransom-EJ
ComodoTrojWare.Win32.Kryptik.FBWM@6gt9t1
F-SecureHeuristic.HEUR/AGEN.1129194
DrWebTrojan.Encoder.4691
TrendMicroRansom_CERBER.SMFD
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
EmsisoftTrojan.Ransom.Cerber.1 (B)
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1129194
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Ransom.Cerber.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Lukitus2.Exp
Acronissuspicious
VBA32BScope.TrojanSpy.Ursnif
MAXmalware (ai score=98)
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/Hexas.HEU
ESET-NOD32a variant of Win32/Kryptik.GADF
TrendMicro-HouseCallRansom_CERBER.SMFD
RisingRansom.Cerber!8.3058 (TFE:dGZlOgK+clzmU2A+UQ)
YandexTrojan.Agent!dZEhURRxtbc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Dridex.IZC!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Ransom.Cerber.HgIASOkA

How to remove Win32/Kryptik.GADF?

Win32/Kryptik.GADF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment