Malware

Win32/Kryptik.GDOC removal instruction

Malware Removal

The Win32/Kryptik.GDOC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GDOC virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GDOC?


File Info:

crc32: E8772596
md5: c8c62e642f721690b3739f24d258efca
name: C8C62E642F721690B3739F24D258EFCA.mlw
sha1: 6b1ab64192f9c51384f673fdd22c1fc9bb6cdfe8
sha256: 23c4340500f28819bfe717fd0e7eef1c51d589f564374caabd54561fe44fa032
sha512: c51e3afa17f7eac6f899fbba6771f86fc0c38d2122cbc9e520ce9a8830e993706b8b18e113daf42d67b5ec57d9757d7ae2bf906d47e4b769f8ca467d0861d431
ssdeep: 24576:6YtiH1CbQBOcW5Dkj+l4wW8YDXm5LWZMkY8Avrb2vcO4z1Pq3eAvI:6YtiHXOxg8W/ATyvcO4z1Pq3eAQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GDOC also known as:

K7AntiVirusTrojan ( 00528e7f1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2682
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacGen:Variant.Zusy.405483
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1385909
SangforTrojan.Win32.Kryptik.1
K7GWTrojan ( 005236cf1 )
Cybereasonmalicious.42f721
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GDOC
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.405483
NANO-AntivirusTrojan.Win32.InstallCube.eygenl
MicroWorld-eScanGen:Variant.Zusy.405483
TencentMalware.Win32.Gencirc.10b3e844
Ad-AwareGen:Variant.Zusy.405483
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GBFV@7jejfn
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-VJ!C8C62E642F72
FireEyeGeneric.mg.c8c62e642f721690
EmsisoftApplication.AdLoad (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dpchc
AviraADWARE/ICLoader.Gen7
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2524971
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Zusy.D62FEB
GDataGen:Variant.Zusy.405483
AhnLab-V3PUP/Win32.ICLoader.R222045
Acronissuspicious
McAfeePacked-VJ!C8C62E642F72
MAXmalware (ai score=100)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.LoadMoney
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!MNd/VX05CiA
IkarusPUA.FileTour
MaxSecureAdware.ICLoader.gen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareX-gen [Adw]

How to remove Win32/Kryptik.GDOC?

Win32/Kryptik.GDOC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment