Malware

Win32/Kryptik.GSDT removal

Malware Removal

The Win32/Kryptik.GSDT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GSDT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine Win32/Kryptik.GSDT?


File Info:

crc32: A697B414
md5: 9a11f42c2b24e5b2733f08a868655007
name: 9A11F42C2B24E5B2733F08A868655007.mlw
sha1: a3af61f3c36bd48529aed7bc2078a2656d0e36e1
sha256: 5a700956c7b5c1646ce452d12e53250a36e22705bebd7154ab5f206033f341dc
sha512: 980c87c502f1ce687ef30325f55245f50a5bce5cd79d2b679015b687a3b3c2cc415e99b4b2f75aab992bd38efa5e9381b717694362e6ac072f1d42805a7d774e
ssdeep: 12288:+WXMig4OynfdlgMetka0ZTP0gEglD1p76uBgkD0ZB8P9TsG/zFVPDG3ZL/MaOcS:+k+kdZTP0gEglD1p7Tib8P9T377yNpO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Disc Soft Ltd Copyright (c) 2014 - . All rights reserved.
InternalName: Practicalities
FileVersion: 4.3.2.868
CompanyName: Disc Soft Ltd
FileDescription: Activisin Au Hairston Unhide Chrak
LegalTrademarks: Disc Soft Ltd Copyright (c) 2014 - . All rights reserved.
Comments: Activisin Au Hairston Unhide Chrak
ProductName: Practicalities
Languages: English
ProductVersion: 4.3.2.868
PrivateBuild: 4.3.2.868
OriginalFilename: Practicalities
Translation: 0x0409 0x04b0

Win32/Kryptik.GSDT also known as:

K7AntiVirusTrojan ( 0054c1a01 )
LionicTrojan.Win32.SpyEyes.4!c
DrWebTrojan.PWS.Stealer.26097
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.31895068
CylanceUnsafe
SangforTrojan.Win32.Occamy.C5A
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanSpy:Win32/SpyEyes.cc2e331d
K7GWTrojan ( 0054c1a01 )
Cybereasonmalicious.c2b24e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GSDT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.Win32.SpyEyes.bhjx
BitDefenderTrojan.GenericKD.31895068
NANO-AntivirusTrojan.Win32.SpyEyes.fpgukb
MicroWorld-eScanTrojan.GenericKD.31895068
TencentWin32.Trojan-spy.Spyeyes.Hsrx
Ad-AwareTrojan.GenericKD.31895068
SophosMal/Generic-S
ComodoMalware@#37iu63eaav2yq
BitDefenderThetaGen:NN.ZexaF.34294.Vu0@ayXHCTli
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_HPURSNIF.SMZD2
McAfee-GW-EditionBehavesLike.Win32.Swizzor.bc
FireEyeGeneric.mg.9a11f42c2b24e5b2
EmsisoftTrojan.GenericKD.31895068 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.SpyEyes.oge
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2B33AB3
MicrosoftTrojan:Win32/Occamy.C5A
ArcabitTrojan.Generic.D1E6AE1C
GDataTrojan.GenericKD.31895068
AhnLab-V3Spyware/Win32.Hpursnif.C3163354
Acronissuspicious
McAfeeArtemis!9A11F42C2B24
VBA32BScope.Trojan.Agent
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_HPURSNIF.SMZD2
YandexTrojanSpy.SpyEyes!yrVptLyZIds
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.1991580.susgen
FortinetW32/Kryptik.GSDT!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GSDT?

Win32/Kryptik.GSDT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment