Malware

About “Win32/Kryptik.GDII” infection

Malware Removal

The Win32/Kryptik.GDII is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GDII virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects information about installed applications
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
w-tf.ru

How to determine Win32/Kryptik.GDII?


File Info:

crc32: 4DB47514
md5: c7d02b108a242814275b15d830a5edaa
name: C7D02B108A242814275B15D830A5EDAA.mlw
sha1: 1fa5ce7b7cc0b87b09e9baab5253fbd2ee32468f
sha256: 237b64462ba0bf68f114d8a8f704f5a01376503680ffa2aa32b8e95b045d960e
sha512: b2464a2b746a9f12acf2d89c2a13cf4fb95b918c992eef44b413b53ab2f27adefe8b9d3aadb6f002309171624512d8a8487e694491db2b09849379fd245b6fef
ssdeep: 49152:qiaoWLFd0c9furUGlDaVucAijcDvlM7TA2+/ENAAK4LalEOgQdGahYo6ejaVZuY:KcD2PcMNAoalPnfhAVfUeQyEYu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GDII also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.779
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.AdLoad.Win32.23504
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.08a242
CyrenW32/S-d2392a22!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GDII
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:AdWare.Win32.AdLoad.adbof
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusRiskware.Win32.AdLoad.eybyez
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10ba56d3
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-R + Mal/EncPk-ZC
ComodoApplication.Win32.AdLoad.GJ@7x6vix
BitDefenderThetaGen:NN.ZexaF.34294.@FW@a0qsrUpi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vt
FireEyeGeneric.mg.c7d02b108a242814
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.EPACK.Gen2
eGambitUnsafe.AI_Score_83%
Antiy-AVLTrojan/Generic.ASMalwS.2483D34
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Heur.Mint.Zamg.1
Acronissuspicious
McAfeePacked-FFF!C7D02B108A24
MAXmalware (ai score=84)
VBA32Adware.AdLoad
MalwarebytesAdware.DLAssistant
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.AdLoad!GzlbTd11r1Y
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Adload
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GDII?

Win32/Kryptik.GDII removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment