Malware

Win32/Kryptik.GDGL removal guide

Malware Removal

The Win32/Kryptik.GDGL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GDGL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

ipv4bot.whatismyipaddress.com
dns1.soprodns.ru
nomoreransom.coin
nomoreransom.bit
dns2.soprodns.ru
gandcrab.bit

How to determine Win32/Kryptik.GDGL?


File Info:

crc32: 99D3F4D2
md5: 856e1ae0aad2cbe072d24db93bd943cd
name: 856E1AE0AAD2CBE072D24DB93BD943CD.mlw
sha1: 27c424a17ee7c0521029e414d0bd305e8093bbfc
sha256: 4f39f8790075dccc48df6a25ce311ac8025c1e86ff05677379a535e3f8283b3a
sha512: 10ff71a549a90659e258729c98d7cc396824b7c7502935ad25c4c85e9ccfaa3093c2304815b2cec37c9bb468e0b2a1bbf904c31f1c7476e20014d8e5494d1002
ssdeep: 6144:zdaZaGB9ivJf8FlhlryfZcEhG97FrSzGq5e3P8AQE59PZ/M/:zqyOFlhhyZGlFMn5K89E59dM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GDGL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BRMon.Gen.3
CAT-QuickHealTrojan.Chapak.ZZ5
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Matrix.tqDs
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003e58dd1 )
BitDefenderTrojan.BRMon.Gen.3
K7GWTrojan ( 0056e9401 )
Cybereasonmalicious.0aad2c
CyrenW32/S-60546053!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.GandCrypt.eybxba
TencentMalware.Win32.Gencirc.10c8833c
Ad-AwareTrojan.BRMon.Gen.3
EmsisoftTrojan.BRMon.Gen.3 (B)
ComodoTrojWare.Win32.Ransom.GandCrab.A@7jk3ar
F-SecureHeuristic.HEUR/AGEN.1117310
DrWebBackDoor.IRC.Bot.3384
ZillyaTrojan.GandCrypt.Win32.69
TrendMicroTSPY_EMOTET.SMB1
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
MaxSecureRansomeware.CRAB.gen
FireEyeGeneric.mg.856e1ae0aad2cbe0
SophosMal/Generic-S + Mal/GandCrab-B
IkarusTrojan-Dropper.Win32.Danabot
JiangminTrojan.GandCrypt.s
AviraHEUR/AGEN.1117310
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt
MicrosoftRansom:Win32/Gandcrab.SF!MTB
ArcabitTrojan.BRMon.Gen.3
SUPERAntiSpywareTrojan.Agent/Gen-Suloc
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.3
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.GandCrypt.C2408947
Acronissuspicious
McAfeePacked-FAG!856E1AE0AAD2
MAXmalware (ai score=99)
VBA32BScope.Trojan.MulDrop
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GDGL
TrendMicro-HouseCallTSPY_EMOTET.SMB1
RisingMalware.Obscure!1.A3BB (CLOUD)
YandexTrojan.GandCrypt!KjMlUglVgUw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.HCUD!tr
BitDefenderThetaGen:NN.ZexaF.34590.tuW@auWlMDb
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.3fa

How to remove Win32/Kryptik.GDGL?

Win32/Kryptik.GDGL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment