Malware

Win32/Kryptik.GNDH removal tips

Malware Removal

The Win32/Kryptik.GNDH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GNDH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Serbian
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

edgedl.me.gvt1.com

How to determine Win32/Kryptik.GNDH?


File Info:

crc32: 841F4C1E
md5: 6932ea0454d25ed2203ccdefd52642f7
name: 6932EA0454D25ED2203CCDEFD52642F7.mlw
sha1: afeaf77fd8502c7903dd79a79b9c5de66c704ef5
sha256: dce0084f9ce3a74f8083e2dc4e6429ca0627d1b89a1bbfdf5060944bd72143a1
sha512: 2df383e1cfe9d2e31fef8e9f208171e65a4c15b985801792449b0e89d7d4c7acc7f9b734b5c47c312c52c2b3902198298b05477e91b714ceabf169500172c29d
ssdeep: 3072:R7dyuPPZgv+Xdu50f9zt6h685Ohn08a1p99DuRkf/bVPgWM7Ocyos+e:R7RP959zsV59fYkf5+Ocyo
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018, ouwecxkuswe
InternalName: unawelno
FileVersion: 1.6.6.1
ProductVersion: 1.4.0.1

Win32/Kryptik.GNDH also known as:

Elasticmalicious (high confidence)
ALYacTrojan.Brsecmon.1
MalwarebytesTrojan.MalPack.GS
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.78d0e9bf
K7GWTrojan ( 005422d51 )
K7AntiVirusTrojan ( 005422d51 )
CyrenW32/Kryptik.MX.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.GNDH
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Chapak.fkpagc
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Chapak.Wofy
SophosMal/Generic-S
ComodoTrojWare.Win32.Injector.EBWP@7y3xky
ZillyaTrojan.Kryptik.Win32.1535586
TrendMicroTrojan.Win32.SODINOK.SM.hp
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Propagate.lw
AviraTR/Crypt.XPACK.wft
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.Brsecmon.1
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.MalCrypted.R246781
MAXmalware (ai score=86)
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingRansom.GandCrab!1.B649 (CLASSIC)
YandexTrojan.GenAsa!g884E42u+rg
IkarusTrojan.Win32.Azorult
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.CUHS!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GNDH?

Win32/Kryptik.GNDH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment