Malware

Win32/Kryptik.GGPQ removal guide

Malware Removal

The Win32/Kryptik.GGPQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGPQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GGPQ?


File Info:

crc32: A858F1CB
md5: c051fe708ba83144d6dbedb8d2a611ce
name: C051FE708BA83144D6DBEDB8D2A611CE.mlw
sha1: 9b6ce7f113e922f9a512fb6b378bb0fb1e6afaa4
sha256: 218c0152b4d6403e42efc86545095b7e7a98dece581915737e1143e141aebf02
sha512: 386ed4e6dc96b3d89c451be46fc7a3f70672ef81ee0c6ba14b0c24ea85110d2b642e0ed7a439f64348c6c8b985b00716f775d20f01e501783ab17a2b4c887ac8
ssdeep: 98304:8iON/h2efld+z3wXR5dztcIZUhsAvKfiLWI4ecw:8iOL/lk3wXR/ztcIKhsAvKfiKI4r
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Aorvoehes isgeh
InternalName: GUMAO.EXE
FileVersion: 1.7.1.6
CompanyName: xa9Aorvoehes isgeh
ProductName: GUMAO
ProductVersion: 1.7.1.6
OriginalFilename: gumao.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.GGPQ also known as:

K7AntiVirusTrojan ( 0052fd2a1 )
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.779
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Occamy.A2
ALYacGen:Variant.Graftor.943584
CylanceUnsafe
ZillyaAdware.AdLoad.Win32.23921
K7GWTrojan ( 0052fd2a1 )
Cybereasonmalicious.08ba83
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GGPQ
APEXMalicious
AvastFileRepMalware
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
BitDefenderGen:Variant.Graftor.943584
NANO-AntivirusRiskware.Win32.AdLoad.fbloqy
MicroWorld-eScanGen:Variant.Graftor.943584
Ad-AwareGen:Variant.Graftor.943584
SophosMal/Generic-R + Mal/EncPk-ABL
ComodoMalware@#tuc1eij155iz
BitDefenderThetaGen:NN.ZexaF.34294.@t0@a8gyRvii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.vh
FireEyeGeneric.mg.c051fe708ba83144
EmsisoftGen:Variant.Graftor.943584 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdware.Adload.fuw
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.261A0E3
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Graftor.943584
AhnLab-V3Malware/Win32.Generic.C2444775
Acronissuspicious
McAfeePacked-FFF!C051FE708BA8
MAXmalware (ai score=98)
VBA32suspected of Malware-Cryptor.FSP.gen
MalwarebytesAdware.DLAssistant
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.94 (RDML:GSJWWVjJdeZHJEr5WG5Ykw)
YandexPUA.AdLoad!/V9VPElpd0M
IkarusPUA.Win32.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FSMR!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.GGPQ?

Win32/Kryptik.GGPQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment