Share via

Trojan W32/Kryptik.DLH.gen!Eldorado removal

Anonymous
2021-11-24T20:51:46+00:00

System Mechanic detected this trojan buried in WildtangentHelper. Was unable to fix. What is the best process to remove said Trojan.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

9 answers

Sort by: Most helpful
  1. Anonymous
    2022-07-08T21:19:58+00:00

    I have both Malwarebytes and Norton and I recently replaced CCLeaner with System Mechanic. I have Real Time protection enabled on both Malwarebytes and Norton. System Mechanic pr5ogram advised I could not enable their version of the Real Time protection, etc. because of incompatibility with Malwarebytes and Norton.

    The System Mechanic full system scan takes at least an hour and both times I did it, it show the W 32 Kryptik.DLH.gen as a risk but "Not fixed". It never shows up on Norton and Malwarebytes. I run full system scans once a day on both Malwarebytes and Norton, threat scans every hour on Malwarebytes, and I clean the files every time I log off or have been on the Internet at many sites so I can start fr3esh visiting more sites. . I cannot find the program on my HP PC, although I have changed settings to display "hidden files". Maddening and frightening. Why did I buy all these programs when 2 of them never even show the threat and the System Mechanic has not Quarantined it or Deleted it - just says "Not fixed." I just hate this digital world where you are under attack at every turn!

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-04-14T00:28:49+00:00

    Same here. It's driving me crazy as the said properties are found in my assignment file which I created it in Visual Studio. The said assignment is a Windows Form App .NET Frameworks (vb.net) and this is driving me crazy as Google detected it as malware and thus blocking me from uploading it. I'm on official build of Windows 11 R3 3500U.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-04-14T01:53:00+00:00

    You're probably coding up actions that look like a virus. That's what antivirus programs have progressed to. They don't just look for exact matches of a particular virus (code signatures), but instead look for patterns of behavior to try to catch new stuff before they have a copy to analyze.

    One issue with that technique is that we sometimes want those kinds of behaviors in a helpful program (false positives). For local stuff you should be able to flag the program as safe, or exclude it from scans.

    But that does nothing for other places/people flagging your code as likely harmful (Google in your example). Might be worth a Stack Overflow search/post. "My program is being flagged as a virus! How do I fix that?" or something similar. Or try to ask Google if you need that functionality and their service.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Ferdinand Nanalig 30,325 Reputation points Independent Advisor
    2021-11-24T21:22:33+00:00

    Hi my name is Ferdinand, I am an Independent Advisor.

    Lets try downloading the free version of Malwarebytes, it is a freeware that you can use to scan, detect and delete viruses like the one you currently have.

    You can download the free version from this link

    https://www.malwarebytes.com/

    Once installed please make a full scan. You may remove this software once you are done with it.

    And follow these additional steps.

    Open up the Task Manager by right clicking the task bar, on the Task Manager window click on more details below then look for the open process associated with the pop up, if you cant see it in the process tab go to the details tab and look for that process then if you see right click it and then go to file location and then once you have located the file delete it.

    Remove temp files and unwanted addons/Extensions in Chrome and Edge

    For Chrome: Open Google Chrome, click the 3 dots at the top right corner click Settings, then on the left pane click Extensions, on the Extensions page look for anything related to the virus then click Remove.

    For new Edge: Open Microsoft Edge, click on the 3 dots at the top right corner then click Extensions, then on the Extensions page, look for any add-ons related to the virus then click Remove.

    Uninstall an unwanted application in Programs and features,

    Go to start type in Control Panel, then go to Programs and then programs and features then go to the list of the programs look for anything unusual or any application that you are not aware right click then uninstall.

    Delete Temporary files off Windows 10.

    Tap Windows Key then R on your keyboard, on the Run box type in %temp% then press enter.

    Once it is up highlight all then delete, if there is a file open that cant be deleted just skip it.

    Hope this helps.

    URL Disclaimer please read.

    Note: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2022-02-20T23:11:11+00:00

    Hi, I System Mechanic detected a similar Trojan on my PC:

    C:\Windows\Installer - W32/Trojan.DBH.gen!Eldorado

    Even though I quarantine and removed, it continues to show up.

    I can't tell what exactly it may be causing damage to.

    I'm also unable to fix this issue.

    I can't tell if this Trojan was received via a Windows 10 update.

    I need help

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments