Malware

Win32/Kryptik.GGQU information

Malware Removal

The Win32/Kryptik.GGQU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GGQU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GGQU?


File Info:

crc32: 5EF312E2
md5: cbdf5de5e48904ed73db68b42f6fb38e
name: CBDF5DE5E48904ED73DB68B42F6FB38E.mlw
sha1: a5671a5a235af5007953ad79b72a47f06d6be735
sha256: 1a204127a54604b73586ca57777773c41751e79ab80d67c2837dc9e8e156da5b
sha512: 208e2eaff7dd795c8ae87847392f074b36e08725daea723b72c401e4babd0d40a42cfe652179ca50672493aeb9f34d1b383aeb374d928798d6e5fac9106ef6b9
ssdeep: 49152:lPZCoDjNP3bSK/vtPTXLmbBS01X5XtOPLNYE/kSe7+X5v9STiUe7X:hZTDjtLS6FSBXXKJ8v0vS2Ue7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Acau enern ispoums
InternalName: DUDEIBELREO.EXE
FileVersion: 3.9.4.7
CompanyName: xa9Acau enern ispoums
ProductName: DUDEIBELREO
ProductVersion: 3.9.4.7
OriginalFilename: dudeibelreo.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.GGQU also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00531cf21 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Zadved.936
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Occamy.A1
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1426785
SangforTrojan.Win32.Save.a
K7GWTrojan ( 00531cf21 )
Cybereasonmalicious.5e4890
CyrenW32/S-af973d5f!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GGQU
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:HEUR:AdWare.Win32.DownloadHelper.vho
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusTrojan.Win32.Kryptik.fcefur
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10ba5a48
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-S
ComodoMalware@#zv1me9wfhqji
BitDefenderThetaAI:Packer.1FFA60B61F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
FireEyeGeneric.mg.cbdf5de5e48904ed
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cddew
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.26275AD
MicrosoftExploit:Win32/ShellCode!ml
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3Trojan/Win32.Generic.C2533624
Acronissuspicious
McAfeePacked-FFF!CBDF5DE5E489
MAXmalware (ai score=99)
VBA32BScope.Adware.StartSurf
PandaTrj/Genetic.gen
YandexTrojan.Agent!z2DTmPA9cwo
IkarusPUA.Win32.Prepscram
FortinetW32/Kryptik.FSMR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GGQU?

Win32/Kryptik.GGQU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment