Malware

Win32/Kryptik.GNDJ removal guide

Malware Removal

The Win32/Kryptik.GNDJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GNDJ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GNDJ?


File Info:

crc32: F6FB96C6
md5: d4675af4c2625ad92403c69cb12557e6
name: D4675AF4C2625AD92403C69CB12557E6.mlw
sha1: 0deed0ce4ff79dd3ac653c693506428f75ab58f1
sha256: 74d6a853a75ed02c765d9eac439d95bc262d96e6fe367bd54bf489fc4c2d4714
sha512: e1aa7098e03205e8d293bfb07083d5dd866bf0d6871c168a7e1ce1e544bd30850ce6484ce5b34fb11e8a374e3b784cbb83196d40e7c644d52ecc9058971984a3
ssdeep: 3072:6qO5MO6MFZiHk/jnwkO7jOJCP3ldQm+WtftlrtLaJdCMJxdZEuNrG:W6MFwHk/jnm7jOaHQmXtvaJdhx
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

InternalName: jteru.ola

Win32/Kryptik.GNDJ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00543e471 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop8.59949
CynetMalicious (score: 100)
ALYacTrojan.Brsecmon.1
CylanceUnsafe
ZillyaTrojan.Chapak.Win32.38509
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Gandcrab.350f8772
K7GWTrojan ( 00543e471 )
Cybereasonmalicious.4c2625
CyrenW32/Kryptik.SH.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GNDJ
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Azorult-7596348-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Chapak.fkqzrp
MicroWorld-eScanTrojan.Brsecmon.1
TencentWin32.Trojan.Generic.Wqct
Ad-AwareTrojan.Brsecmon.1
SophosMal/Generic-S + Mal/GandCrab-G
ComodoTrojWare.Win32.Chapak.LB@7zyuc7
BitDefenderThetaGen:NN.ZexaF.34670.ku0@a4GEsXie
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.GANDCRAB.SMKLI.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.d4675af4c2625ad9
EmsisoftTrojan.Brsecmon.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Chapak.ady
AviraHEUR/AGEN.1107206
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Chapak
MicrosoftTrojan:Win32/Gandcrab.VRD!MTB
ArcabitTrojan.Brsecmon.1
AegisLabTrojan.Win32.Chapak.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Brsecmon.1
AhnLab-V3Malware/Gen.Generic.C2855150
Acronissuspicious
McAfeeGenericRXGQ-DY!D4675AF4C262
VBA32BScope.Trojan.Vigorf
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.GANDCRAB.SMKLI.hp
RisingTrojan.Kryptik!1.B50A (CLOUD)
YandexTrojan.GenAsa!85YM+61oA6c
IkarusTrojan.Win32.Gandcrab
FortinetW32/Generic.AP.23529E!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCuX8A

How to remove Win32/Kryptik.GNDJ?

Win32/Kryptik.GNDJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment