Malware

Should I remove “Win32/Kryptik.GDCD”?

Malware Removal

The Win32/Kryptik.GDCD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GDCD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Win32/Kryptik.GDCD?


File Info:

crc32: 8D905E7F
md5: a53618973afc705e9a123b084976c166
name: A53618973AFC705E9A123B084976C166.mlw
sha1: 624d6445ed8ae417839e02f300472c7f04d07648
sha256: 4ef69a181f31fbf41815c6c78be1328b7d8ba1e65323e13eb455765605000a23
sha512: ea0e87fb4dc1252f0a755de4ea69dc1d79f33c2067ee71291d183978717430654384e57cdefac18ae9f51903e8d13597602bdb4f79ed1e81a62455324000eec0
ssdeep: 6144:jZJNhuNmse02+DrcuoCjccpS7RgjdQpagsTDYSf08:TNh9se02+D4lcpS9ad4LsTDC8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GDCD also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Emotet.Gen.3
FireEyeGeneric.mg.a53618973afc705e
CAT-QuickHealTrojan.Chapak.ZZ6
McAfeePacked-ZG!A53618973AFC
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderTrojan.Emotet.Gen.3
K7GWTrojan ( 0052743e1 )
Cybereasonmalicious.73afc7
BitDefenderThetaGen:NN.ZexaF.34590.syW@aut7KNj
CyrenW32/S-135e99c5!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packed.Gandcrab-6502433-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Banker1.exzppm
ViRobotTrojan.Win32.Ransom.302592.J
TencentMalware.Win32.Gencirc.10b588ba
Ad-AwareTrojan.Emotet.Gen.3
SophosMal/Generic-R + Mal/GandCrab-A
ComodoTrojWare.Win32.Cloxer.AY@7o68fu
F-SecureHeuristic.HEUR/AGEN.1103299
DrWebTrojan.PWS.Banker1.25405
ZillyaTrojan.GandCrypt.Win32.78
TrendMicroRansom_HPGANDCRAB.SMONT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Emotet.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1103299
MAXmalware (ai score=98)
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt
MicrosoftRansom:Win32/GandCrab!rfn
ArcabitTrojan.Emotet.Gen.3
SUPERAntiSpywareRansom.GandCrypt/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Emotet.Gen.3
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.GandCrypt.C2407383
Acronissuspicious
VBA32TrojanRansom.GandCrypt
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GDCD
TrendMicro-HouseCallRansom_HPGANDCRAB.SMONT
RisingTrojan.Kryptik!1.B048 (CLOUD)
YandexTrojan.GenAsa!M7GRZmxDq18
IkarusTrojan-Downloader.Win32.Zurgop
FortinetW32/GenKryptik.BAPN!worm
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.c3b

How to remove Win32/Kryptik.GDCD?

Win32/Kryptik.GDCD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment