Malware

Win32/Kryptik.GMVQ removal tips

Malware Removal

The Win32/Kryptik.GMVQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GMVQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GMVQ?


File Info:

crc32: BA3B11D4
md5: 72c3d8b1286a2b61045fcb67b14fb245
name: 72C3D8B1286A2B61045FCB67B14FB245.mlw
sha1: 8622c7800a203ebe7ff40f0ec57fa7a7cb76efc7
sha256: 5fc77dff87c499f0ae8d7c34e45b54293be7910862cdc3cb85f3cc75847983fe
sha512: 6289e303b6a658593a7f085a8f4303dcf6388e108756f386b0a669e52bde93cdfe03d8e2d22917d87e04e223420fa780ae7d9b37d16a58a1219d3f93296109c4
ssdeep: 6144:cKF438+zBK1Vb5dSVL+pwXaCl14hrSXVagj:cKt+VK1Vb5LC14gj
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows

Version Info:

FileVersion: 1.0.2.12
ProductVersion: 1.0.4
Translation: 0x0339 0x04b0

Win32/Kryptik.GMVQ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00542eb91 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24943
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S4357176
ALYacTrojan.GenericKDZ.51236
CylanceUnsafe
ZillyaTrojan.Stealer.Win32.2615
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.f61ee5cc
K7GWTrojan ( 00542eb91 )
Cybereasonmalicious.1286a2
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GMVQ
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Pwsx-9849949-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.51236
NANO-AntivirusTrojan.Win32.Stealer.fkkpzc
MicroWorld-eScanTrojan.GenericKDZ.51236
TencentWin32.Trojan-spy.Stealer.Ahyh
Ad-AwareTrojan.GenericKDZ.51236
SophosMal/Generic-R + Mal/GandCrab-G
ComodoTrojWare.Win32.Ransom.Crypmod.AE@7xspg9
BitDefenderThetaGen:NN.ZexaF.34294.rC0@aWZkVXdG
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
FireEyeGeneric.mg.72c3d8b1286a2b61
EmsisoftTrojan.GenericKDZ.51236 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.dtn
AviraHEUR/AGEN.1106537
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2968ECA
MicrosoftTrojan:Win32/Wacatac.B!ml
SUPERAntiSpywarePUP.InstallCore/Variant
GDataTrojan.GenericKDZ.51236
AhnLab-V3Trojan/Win.MalPe.X2055
McAfeeTrojan-FQIC!72C3D8B1286A
MAXmalware (ai score=82)
VBA32BScope.Trojan.Cutwail
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingSpyware.Agent!1.B64D (CLASSIC)
YandexTrojan.GenAsa!b9rKAN85rIc
IkarusTrojan.Win32.Danabot
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GMUU!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.GMVQ?

Win32/Kryptik.GMVQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment