Malware

Should I remove “Win32/Kryptik.GLDE”?

Malware Removal

The Win32/Kryptik.GLDE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GLDE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Win32/Kryptik.GLDE?


File Info:

crc32: B92BCCE1
md5: 31530036467445292bc2687d4c770db9
name: 31530036467445292BC2687D4C770DB9.mlw
sha1: 1179d27559f1f3bcaf96c0521a3d8c7b3ab9503c
sha256: ced550ad0fc5ae32655080a35cc7c22f0fb9526f5f0d9f1d1e6ebe74f0d276ea
sha512: 5238fe9682ab46c288a81572a13ae18a1f0a08fe4840e3a183e981a522df946538362a626a918b39c2bb5063c498424c62455ac05cc1c93c79d31b00e5c54b29
ssdeep: 24576:FI6PEyp4ab56VZXa3/9O1QhI+VUQb/RKRPT4HFlMN4lbs6NNX9gO:FI6PE4bzFCw/SPTi4mx
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: (C)TechSmith Corporation 2007-2015
InternalName: Runaway Connectpage
FileVersion: 7.4.6.5
CompanyName: TechSmith Corporation
PrivateBuild: 7.4.6.5
LegalTrademarks: (C)TechSmith Corporation 2007-2015
Comments: Myfilter Cntinuum Common
ProductName: Runaway Connectpage
ProductVersion: 7.4.6.5
FileDescription: Myfilter Cntinuum Common
OriginalFilename: Runaway Connectpage
Translation: 0x0409 0x04b0

Win32/Kryptik.GLDE also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056e9b11 )
LionicTrojan.Win32.Shade.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CynetMalicious (score: 100)
ALYacGen:Variant.Brresmon.126
CylanceUnsafe
ZillyaAdware.Shade.Win32.4
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Shade.37d42f6d
K7GWTrojan ( 0056e9b11 )
Cybereasonmalicious.646744
ESET-NOD32a variant of Win32/Kryptik.GLDE
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Shade.owd
BitDefenderGen:Variant.Brresmon.126
NANO-AntivirusTrojan.Win32.Kryptik.fiivva
MicroWorld-eScanGen:Variant.Brresmon.126
TencentWin32.Trojan.Shade.Lhdb
Ad-AwareGen:Variant.Brresmon.126
SophosMal/Generic-S
ComodoMalware@#1klm9sdkgxk5x
BitDefenderThetaGen:NN.ZexaF.34126.vnKfa03lBTki
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
FireEyeGen:Variant.Brresmon.126
EmsisoftGen:Variant.Brresmon.126 (B)
AviraHEUR/AGEN.1137337
Antiy-AVLTrojan/Generic.ASMalwS.2875039
MicrosoftRansom:Win32/Troldesh.A
GDataGen:Variant.Brresmon.126
AhnLab-V3Malware/Win32.Generic.C2737263
McAfeeArtemis!315300364674
VBA32BScope.TrojanPSW.Fareit
MalwarebytesMalware.AI.1034233746
PandaTrj/GdSda.A
YandexTrojan.Shade!wRs9YaV8EZA
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.GLDE!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GLDE?

Win32/Kryptik.GLDE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment