Malware

Win32/Kryptik.GLRQ removal tips

Malware Removal

The Win32/Kryptik.GLRQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GLRQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.GLRQ?


File Info:

name: 49555B249CA287930D61.mlw
path: /opt/CAPEv2/storage/binaries/599a4920cdcab62e5f58af6e6cdfd25ed5a11a8670c599ec7706fb1a6adae6d0
crc32: 4FAA3B6F
md5: 49555b249ca287930d618f6fc6d8e177
sha1: 07b3ee8d0cdf2ff5e223979925e6dee15c9e7bb7
sha256: 599a4920cdcab62e5f58af6e6cdfd25ed5a11a8670c599ec7706fb1a6adae6d0
sha512: 1c3852d1b2892e3f1d10b41ddd1ba310f6555af2fcbe3b009ff5ac6289044d58e856c7cbb3c16a72da7af69e5357ecb74d241c5177144e40118bbb9885ca60e4
ssdeep: 12288:of0AEgEAmMzBqo7GOm5c2tseNucTJ4bgrgBiwP/s8OUly0uWZ0G/uePu2TG172:ofowY5cisgucTl0P7l3utuuag
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108252334F1DA6623C0272F371872EA0682BD7A32545215DB1B888D3EA7771C1EB36677
sha3_384: c7e84703e02bb6531d45119e322b588e1defd62bfeaab3315d0a2daa0781e0719d70e6daea52bd3a10f27b7a57d0bd8f
ep_bytes: 558bec6aff68c05c410068d01d400064
timestamp: 2016-09-19 10:50:04

Version Info:

0: [No Data]

Win32/Kryptik.GLRQ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Swizzor.l8Pw
FireEyeGeneric.mg.49555b249ca28793
CAT-QuickHealSwBndlr.Unwaders.AB9
SkyhighBehavesLike.Win32.Dropper.dc
McAfeePacked-FKC!49555B249CA2
Cylanceunsafe
ZillyaAdware.StartSurf.Win32.59935
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaAdWare:Win32/StartSurf.6f6982d8
K7GWTrojan ( 0053e8a41 )
K7AntiVirusTrojan ( 0053e8a41 )
BitDefenderThetaGen:NN.ZexaF.36744.7uW@aqkwtmki
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GLRQ
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0PB124
Kasperskynot-a-virus:AdWare.Win32.StartSurf.dksh
NANO-AntivirusRiskware.Win32.StartSurf.fjdhrx
AvastWin32:Kryptik-PRB [Adw]
TencentMalware.Win32.Gencirc.1158b357
F-SecureHeuristic.HEUR/AGEN.1343795
DrWebTrojan.Vittalia.13656
TrendMicroTROJ_GEN.R002C0PB124
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.mqc
AviraHEUR/AGEN.1343795
Antiy-AVLGrayWare/Win32.Unwaders
Kingsoftmalware.kb.a.1000
MicrosoftSoftwareBundler:Win32/Prepscram.E
ZoneAlarmnot-a-virus:AdWare.Win32.StartSurf.dksh
CynetMalicious (score: 100)
VBA32BScope.Adware.DownloadHelper
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.StartSurf!DOSPYNA7vtg
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIST!tr
AVGWin32:Kryptik-PRB [Adw]
Cybereasonmalicious.d0cdf2
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.GLRQ?

Win32/Kryptik.GLRQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment