Malware

Win32/Kryptik.GMQT information

Malware Removal

The Win32/Kryptik.GMQT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GMQT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Win32/Kryptik.GMQT?


File Info:

crc32: BEF0754B
md5: 294ed7c7ab225b2815db0a30b4fae082
name: 294ED7C7AB225B2815DB0A30B4FAE082.mlw
sha1: 9b290824c9010a24c694d655611a85395a9bd14b
sha256: c240d3a79db22880f25b8a618fb282084f285dc1b01cc6f4747a70c30be7e36e
sha512: ded3a5ee9a9247b8356eb4558d4621f861a04d7f979297cca824f319359c9de9addf7dde31cbf2319ac27938ef4fa046028664b0f4fde7e7f0396956d81f2c8b
ssdeep: 6144:NoTp1DCmHfVgCq5t2h3WViKqevjsLb8tPriB0:NKp1lgCq5U3WVrjsvmc0
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

FileVersion: 1.0.0.12
ProductVersion: 1.0.0.12
Translation: 0x0639 0x04b0

Win32/Kryptik.GMQT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053d5971 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24943
ClamAVWin.Packed.addsub-6963063-0
ALYacTrojan.Ransom.GandCrab
MalwarebytesRansom.GandCrab
ZillyaTrojan.GandCrypt.Win32.1294
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Genasom.ali1000102
K7GWTrojan ( 0053d5971 )
Cybereasonmalicious.7ab225
CyrenW32/Kryptik.NK.gen!Eldorado
SymantecRansom.GandCrab
ESET-NOD32a variant of Win32/Kryptik.GMQT
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.BRMon.Gen.4
NANO-AntivirusTrojan.Win32.Stealer.fkcplm
ViRobotTrojan.Win32.GandCrab.244736
MicroWorld-eScanTrojan.BRMon.Gen.4
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.BRMon.Gen.4
SophosMal/Generic-R + Mal/GandCrab-G
ComodoTrojWare.Win32.TrojanDownloader.Vigorf.QT@7ztk1a
BitDefenderThetaGen:NN.ZexaF.34050.oC0@a04sIdfG
TrendMicroRansom_GANDCRAB.THAAADAH
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.dh
FireEyeGeneric.mg.294ed7c7ab225b28
EmsisoftTrojan.BRMon.Gen.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.dte
AviraHEUR/AGEN.1106537
Antiy-AVLTrojan/Generic.ASMalwS.295BE15
ArcabitTrojan.BRMon.Gen.4
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.BRMon.Gen.4
AhnLab-V3Trojan/Win.MalPe.X2055
Acronissuspicious
McAfeeGenericRXGP-BB!294ED7C7AB22
VBA32BScope.Trojan.Packed
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_GANDCRAB.THAAADAH
RisingSpyware.Agent!1.B64D (CLASSIC)
IkarusTrojan.Win32.Krypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GMSM!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Generic.HwoCPecA

How to remove Win32/Kryptik.GMQT?

Win32/Kryptik.GMQT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment