Malware

What is “Win32/Kryptik.GCQE”?

Malware Removal

The Win32/Kryptik.GCQE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GCQE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
c-vv.ru

How to determine Win32/Kryptik.GCQE?


File Info:

crc32: 8AA99ECB
md5: 0aa9678d2b23f4ca11d78e092545df44
name: 0AA9678D2B23F4CA11D78E092545DF44.mlw
sha1: 143d0476ee0ad479b8b2f1fdf1814d1659af0e7d
sha256: 1a35b98fb86626393f64aaa54e645a05c469343972de877b9d5d9863ef6ab654
sha512: cc78ef327b4dd0033bcf69b46fec0b851b61ab4a1f9338f0179bc217ec77e8cd34a3be93cd06b4f930969ea3627e00058718866fbd53907dc951bbfe72830c1a
ssdeep: 98304:tZmh95gwzZK2cM70Y3DN+ZTxa/wK5zG9b:tZmv3zZzc20UQZNO8V
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.GCQE also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005375761 )
LionicTrojan.Win32.Snojan.tpqJ
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.779
CAT-QuickHealTrojan.Occamy.A1
ALYacGen:Heur.Mint.Zamg.1
MalwarebytesAdware.DLAssistant
ZillyaAdware.AdLoad.Win32.24057
SangforTrojan.Win32.Save.a
BitDefenderGen:Heur.Mint.Zamg.1
K7GWTrojan ( 00535cb51 )
Cybereasonmalicious.d2b23f
CyrenW32/S-0aac19d0!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GCQE
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
NANO-AntivirusRiskware.Win32.AdLoad.feuclz
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10ba5074
Ad-AwareGen:Heur.Mint.Zamg.1
SophosGeneric PUA BE (PUA)
ComodoTrojWare.Win32.Trojan.XPack.~gen1@1rwlif
BitDefenderThetaGen:NN.ZexaF.34236.@tW@a42MSdbi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VirRansom.rh
FireEyeGeneric.mg.0aa9678d2b23f4ca
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.wfpo
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.26D28BC
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Malware/Win32.Generic.C2596986
Acronissuspicious
McAfeePacked-FKC!0AA9678D2B23
MAXmalware (ai score=100)
VBA32BScope.Adware.AdLoad
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.AdLoad!yKIYezuYFJk
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FSMR!tr
PandaTrj/Genetic.gen

How to remove Win32/Kryptik.GCQE?

Win32/Kryptik.GCQE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment