Malware

About “Win32/Kryptik.GDHN” infection

Malware Removal

The Win32/Kryptik.GDHN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GDHN virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GDHN?


File Info:

crc32: B44F8009
md5: 712ffc560692ee3bd9a2b05909f5a736
name: 712FFC560692EE3BD9A2B05909F5A736.mlw
sha1: b5d4b539dae26c9a4eb4db9ccb0f0e0be21187bd
sha256: 1e00e636c65aa3959a20a26a11a64c347cb6a2420b34c1955c0fa7cc3ba38050
sha512: f0a86f1241c215e2c81d9d146fd230c0e158884ce12f406bdb0d46d5a6eb74c8c1641e6ce831935c3e60e2c33a430b0aeaea5e91eae8765b51940eee479af234
ssdeep: 24576:b+lhkZo/f8TJO3Q7wmXpj+l4wW8YDXm5LWZMkY8Avrb2vcO4z1Pq3eAvI8:b+io8T8iwm/8W/ATyvcO4z1Pq3eAQ8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GDHN also known as:

K7AntiVirusTrojan ( 00527b2f1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2666
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacGen:Variant.Fragtor.4635
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3158579
SangforTrojan.Win32.Kryptik.1
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Katusha.2515e166
K7GWTrojan ( 00527b2f1 )
Cybereasonmalicious.60692e
CyrenW32/Kryptik.ECL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GDHN
APEXMalicious
AvastWin32:AdwareSig [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.ICLoader.gen
BitDefenderGen:Variant.Fragtor.4635
NANO-AntivirusTrojan.Win32.InstallCube.eydfuu
MicroWorld-eScanGen:Variant.Fragtor.4635
TencentMalware.Win32.Gencirc.10b3e8c0
Ad-AwareGen:Variant.Fragtor.4635
SophosGeneric PUA LF (PUA)
ComodoApplication.Win32.ICLoader.GDGG@7ivzmg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXEO-DM!712FFC560692
FireEyeGeneric.mg.712ffc560692ee3b
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.cag
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.24DCE14
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Fragtor.D121B
GDataWin32.Application.ICLoader.F
AhnLab-V3PUP/Win32.ICLoader.R221740
Acronissuspicious
McAfeeGenericRXEO-DM!712FFC560692
MAXmalware (ai score=100)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.ICLoader
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!ebKWezt/vqY
IkarusPUA.Win32.ICLoader
MaxSecureAdware.ICLoader.gen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]

How to remove Win32/Kryptik.GDHN?

Win32/Kryptik.GDHN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment