Malware

Win32/Kryptik.ZDG removal

Malware Removal

The Win32/Kryptik.ZDG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ZDG virus can do?

  • At least one process apparently crashed during execution
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.ZDG?


File Info:

name: E82880E81BABA7A9C693.mlw
path: /opt/CAPEv2/storage/binaries/009cded4eaacf161f5e4e8994d2349524b68d7d4a409fe2583fa426accb52920
crc32: 425BB194
md5: e82880e81baba7a9c6939884d9789eae
sha1: fc2c41edd300540c30b39b752dac39f7c328e1c7
sha256: 009cded4eaacf161f5e4e8994d2349524b68d7d4a409fe2583fa426accb52920
sha512: 7a88bb7d8d06753a89d32ddb8ac1ad8721db83c2b3c8b1f319daabdf1ba4f4e70b1ef8765c651496fe7199ac1fb6efe5d63971dc80e89b9560c9e603d2aa7feb
ssdeep: 6144:y1+VmPaeGyhdtnspJhKmH80tSaqvKS0EmJDsxlqVt:y4sSLEQpJhiCSAy2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A44C0E2A608C041D8356277CB15C85B832C1F369E9B3ABD516C3F58F3F42C25AD5EA9
sha3_384: 4b79ccf213ce63b6f6e35cd6d8c01a8e848b198a8147ea33f770e1db473968b85aa4a54920abe5043358a63f4f26699e
ep_bytes: 6856bb4000c347b9279523abec5dc955
timestamp: 2011-01-12 07:37:58

Version Info:

CompanyName: Don HO don.h@free.fr
FileDescription: Notepad++ : a free (GNU) source code editor
FileVersion: 5.7
InternalName: npp.exe
LegalCopyright: Copyleft 1998-2006 by Don HO
OriginalFilename: Notepad++.exe
ProductName: Notepad++
ProductVersion: 5.7
Translation: 0x0409 0x04b0

Win32/Kryptik.ZDG also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e82880e81baba7a9
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeeDownloader-ASH.gen.g
CylanceUnsafe
VIPRELookslike.Win32.Sirefef.zh (v)
SangforSpyware.Win32.Zbot.8
K7AntiVirusTrojan ( 004f11e51 )
AlibabaTrojan:Win32/Kryptik.0ebef5fd
K7GWTrojan ( 0034c9011 )
Cybereasonmalicious.81baba
BitDefenderThetaGen:NN.ZexaF.34212.pC1@amWnDkci
CyrenW32/FakeNPP.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ZDG
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Symmi.31944
NANO-AntivirusTrojan.Win32.Zbot.rgeln
MicroWorld-eScanGen:Variant.Symmi.31944
AvastWin32:Reveton-Y [Trj]
TencentMalware.Win32.Gencirc.10c18021
Ad-AwareGen:Variant.Symmi.31944
EmsisoftGen:Variant.Symmi.31944 (B)
ComodoTrojWare.Win32.Spy.Zbot.QRC@4me3zw
DrWebTrojan.Siggen8.20373
ZillyaTrojan.Zbot.Win32.51733
TrendMicroTSPY_ZBOT.SMES
McAfee-GW-EditionBehavesLike.Win32.Infected.dh
SophosMal/Generic-S + Mal/EncPk-ABFO
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.31944
JiangminTrojanSpy.Zbot.bnev
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.EPACK.Gen2
MAXmalware (ai score=99)
ArcabitTrojan.Symmi.D7CC8
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Dynamer!ac
AhnLab-V3Spyware/Win32.Zbot.C1461855
Acronissuspicious
VBA32Malware-Cryptor.General.3
ALYacGen:Variant.Symmi.31944
TACHYONTrojan-Spy/W32.ZBot.261632.AO
MalwarebytesMalware.AI.1653375674
TrendMicro-HouseCallTSPY_ZBOT.SMES
RisingSpyware.Zbot!8.16B (C64:YzY0OmUdxdThXYHW)
YandexTrojan.GenAsa!G/3YIhLJCCs
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Kryptik.ZFQ!tr
AVGWin32:Reveton-Y [Trj]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.ZDG?

Win32/Kryptik.ZDG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment