Malware

Should I remove “Win32/Kryptik.GFDU”?

Malware Removal

The Win32/Kryptik.GFDU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GFDU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Anomalous binary characteristics

Related domains:

imy-i.ru

How to determine Win32/Kryptik.GFDU?


File Info:

crc32: E82E6184
md5: 0185a96dcd1088f8bf8a395e968809f6
name: 0185A96DCD1088F8BF8A395E968809F6.mlw
sha1: dedb59aa8ed8278e4bbc7bf9efb56b0a29b5164c
sha256: 1a2100cf7376ed76ff763e83052303076b6f4f8e7d6ce8e595d48db9edb47abd
sha512: e9f945a71d8a38dcf8a010b29d67735bb5c0fa0d291dc83cf0b9c1810457704837a03eb62f7976fe4501f98353627892992740d49c3b5d028f8d6bde49e07ac3
ssdeep: 49152:tjLhWLgj3ubHAGO9YRYPu1TSToi3XfX4Vl2exa7XNEZP//p+VZ4ZHIqJslQAerT:txW8/sQfs5EVKZBJslQAeP6M2fr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Btaahansaafab heetr affaorhahew
InternalName: ELLOD.EXE
FileVersion: 3.5.8.6
CompanyName: xa9Btaahansaafab heetr affaorhahew
ProductName: ELLOD
ProductVersion: 3.5.8.6
OriginalFilename: ellod.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.GFDU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052cbd11 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.936
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Occamy.A1
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1437234
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0052cbd11 )
Cybereasonmalicious.dcd108
CyrenW32/S-71ed512d!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GFDU
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:VHO:AdWare.Win32.StartSurf.gen
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusTrojan.Win32.Snojan.fdyjdd
MicroWorld-eScanGen:Heur.Mint.Zamg.1
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34236.@t0@aCIw3Rji
McAfee-GW-EditionPacked-FFF!0185A96DCD10
FireEyeGeneric.mg.0185a96dcd1088f8
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminDownloader.Snojan.aup
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.26966A0
MicrosoftSoftwareBundler:Win32/Dlhelper
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Malware/Win32.Generic.C2570983
Acronissuspicious
McAfeePacked-FFF!0185A96DCD10
MAXmalware (ai score=95)
VBA32BScope.Downloader.Snojan
MalwarebytesAdware.RussAd
PandaTrj/CI.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexTrojan.GenAsa!0gpax7svokY
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GGDT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GFDU?

Win32/Kryptik.GFDU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment