Malware

Should I remove “Win32/Kryptik.GDHI”?

Malware Removal

The Win32/Kryptik.GDHI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GDHI virus can do?

  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GDHI?


File Info:

crc32: FCA2044E
md5: bb5ba0d6ea14e862cca589db88131ed6
name: BB5BA0D6EA14E862CCA589DB88131ED6.mlw
sha1: aa6c1ae81fcdf1461495399c02c7b5cc4ce93af0
sha256: 4fadc88c363be9107704a4c4070f386ab991b687dc80d43cdcf2ef2531698837
sha512: 734394a5d0c03702c211848ed152f727ad6e9ed4f05f6d732cf74aadd3f0b3f16b49f24510efaf67f85e92ca5df505559227b17625f50dd03825b6deb2bdb855
ssdeep: 6144:U/txZm50ivzndwh5WSnPujHsBmPCegD9LAa0d06:ytxc0GznODtmMBmP/gZOt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GDHI also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BRMon.Gen.3
FireEyeGeneric.mg.bb5ba0d6ea14e862
CAT-QuickHealRansom.GandCrab.ZZ6
Qihoo-360Win32/Trojan.56c
ALYacTrojan.BRMon.Gen.3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderTrojan.BRMon.Gen.3
K7GWTrojan ( 0052782d1 )
Cybereasonmalicious.6ea14e
CyrenW32/S-c07995ba!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Banker1.eycucn
ViRobotTrojan.Win32.Ransom.286208.D
RisingTrojan.Kryptik!1.B048 (RDMK:cmRtazo0wLmCoAQOFYgR62Fx1a+w)
Ad-AwareTrojan.BRMon.Gen.3
EmsisoftTrojan.BRMon.Gen.3 (B)
ComodoTrojWare.Win32.Cloxer.AY@7o68fu
F-SecureHeuristic.HEUR/AGEN.1103299
DrWebTrojan.PWS.Banker1.25780
ZillyaTrojan.GandCrypt.Win32.80
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosML/PE-A + Mal/GandCrab-A
IkarusTrojan.Win32.Agentb
JiangminTrojan.GandCrypt.r
AviraHEUR/AGEN.1103299
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Gandcrab.K!MTB
ArcabitTrojan.BRMon.Gen.3
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.3
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Magniber.R220633
Acronissuspicious
McAfeeGenericRXEC-RH!BB5BA0D6EA14
VBA32TrojanRansom.GandCrypt
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
ZonerTrojan.Win32.66266
ESET-NOD32a variant of Win32/Kryptik.GDHI
TrendMicro-HouseCallMal_HPGen-37b
TencentMalware.Win32.Gencirc.10b20e42
YandexTrojan.GenAsa!d81jhQYWnno
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.CNAR!tr
BitDefenderThetaGen:NN.ZexaF.34590.ryW@a4k6nIj
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureRansomeware.GandCrypt.JZ

How to remove Win32/Kryptik.GDHI?

Win32/Kryptik.GDHI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment