Malware

Win32/Kryptik.GMDU removal

Malware Removal

The Win32/Kryptik.GMDU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GMDU virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network anomalies occured during the analysis.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GMDU?


File Info:

crc32: D36E33FF
md5: 8680669b7abf36356460dfd44c7e6e13
name: 8680669B7ABF36356460DFD44C7E6E13.mlw
sha1: 5d67e9306d8be7cb553e77b6b8bb12038617ce4f
sha256: 1dd1c37758cf9355faadfaee45e76772c5620a62ddcb7a5d9033c6cbb6d56a46
sha512: be14d77b4658eb4fa9b9a8bc90ab810da873477bfdccbc00c6ebaf33104e180bb5ab6feb4a68f256cc3dc6ca4aee52d852a9ba2c851c8d82cc4dd81ad5a473e9
ssdeep: 49152:iiDU7MtTeMYOzAm7SPGn4J1OeMVwKFDKC+lRAOQx:imKMtTeWAm7SPGn6MtDKjffy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Downloader_5.32.0.6141
ProductName: Downloader_5.32.0.6141
FileVersion: 5.32.0.6141
ProductVersion: 5.32.0.6141
FileDescription: Downloader 5.32.0.6141
Translation: 0x0409 0x04b0

Win32/Kryptik.GMDU also known as:

K7AntiVirusTrojan ( 0053e8521 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3812
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.397725
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.14522
SangforTrojan.Win32.Azorult.gen
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Katusha.4853e95c
K7GWTrojan ( 0053e8521 )
Cybereasonmalicious.b7abf3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMDU
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.397725
NANO-AntivirusTrojan.Win32.InstallCube.fjtsxc
MicroWorld-eScanGen:Variant.Zusy.397725
TencentMalware.Win32.Gencirc.10b637d7
Ad-AwareGen:Variant.Zusy.397725
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34266.Dt1@aaIbWYoi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-FME!8680669B7ABF
FireEyeGeneric.mg.8680669b7abf3635
EmsisoftApplication.ICLoader (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.umg
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28E58D7
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Zusy.D6119D
GDataGen:Variant.Zusy.397725
AhnLab-V3PUP/Win32.ICLoader.R241878
Acronissuspicious
McAfeePacked-FME!8680669B7ABF
MAXmalware (ai score=100)
VBA32BScope.Trojan.InstallCube
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!uacqKJ/K940
IkarusPUA.FileTour
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GMDU?

Win32/Kryptik.GMDU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment