Malware

Win32/Kryptik.GDAI removal

Malware Removal

The Win32/Kryptik.GDAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GDAI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GDAI?


File Info:

crc32: AAC80C00
md5: 527307bc11517d765b0e20231cae4e7b
name: 527307BC11517D765B0E20231CAE4E7B.mlw
sha1: 8803bf4ae701b5a291252f12769f2b1765438457
sha256: 80da52fbe837b905ec7b1068b6498a9cf43d03a783816f5781e8ceb7327aaaaf
sha512: 1073492685d4231ce261bff64c4e81ef415f8dade2d287eb5da3809c04a25c6806c8f3681e84f55b89149e6b4f8832544ba8c34dc8a7a53e0e47803b5272108f
ssdeep: 1536:ixgQpUy9b05N24HiFEIbO9yovYU28nYn4fFk/a1EwpA0oKvP7tcoIlml+a:iOyt05BPyd8/h1E8AdKrtcoIQlV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, ignomfdoudeb
FileVersion: 10.1.10.11
ProductVersion: 10.1.10.11
Translation: 0x0809 0x04b0

Win32/Kryptik.GDAI also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00526cba1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24384
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.Mint.Jamg.C
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 00526cba1 )
Cybereasonmalicious.c11517
CyrenW32/S-c5d37cab!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GDAI
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Ransom.Win32.GandCrypt.gen
BitDefenderTrojan.Mint.Jamg.C
NANO-AntivirusTrojan.Win32.NeutrinoPOS.exyoft
MicroWorld-eScanTrojan.Mint.Jamg.C
TencentTrojan.Win32.Gandcrypt.c
Ad-AwareTrojan.Mint.Jamg.C
SophosMal/Generic-S + Mal/GandCrab-B
ComodoTrojWare.Win32.NeutrinoPOS.C@7ise8z
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_EMOTET.SMB1
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.527307bc11517d76
EmsisoftTrojan.Mint.Jamg.C (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.GandCrypt.ao
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1126869
eGambitUnsafe.AI_Score_97%
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.Mint.Jamg.C
AegisLabTrojan.Win32.GandCrypt.tpix
ZoneAlarmHEUR:Trojan-Ransom.Win32.GandCrypt.gen
GDataTrojan.Mint.Jamg.C
AhnLab-V3Trojan/Win32.RansomCrypt.R220259
Acronissuspicious
McAfeeGenericRXEB-KP!527307BC1151
MAXmalware (ai score=96)
VBA32TrojanBanker.NeutrinoPOS
MalwarebytesTrojan.Bunitu
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_EMOTET.SMB1
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
IkarusTrojan.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GLKY!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Ransom.013

How to remove Win32/Kryptik.GDAI?

Win32/Kryptik.GDAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment