Malware

Win32/Kryptik.GPQX (file analysis)

Malware Removal

The Win32/Kryptik.GPQX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GPQX virus can do?

  • Unconventionial binary language: Tamil
  • Unconventionial language used in binary resources: Gaelic
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win32/Kryptik.GPQX?


File Info:

crc32: AAE39681
md5: 7b0e7c40e3f384bf3c289943e2aaac8f
name: 7B0E7C40E3F384BF3C289943E2AAAC8F.mlw
sha1: defb7963a30fdcbc2d4e516d20dd74f7c2322c15
sha256: 5a5fd5612c037297815a3b8f66d10def4e4457181665c58b31aa20942eacd161
sha512: decb84f67a1bdcb4bac24d72763efcc6f074cfe4da578d30959160babf4db94eaf165808668c5411e0bc220d0e9584dfbfa6934558ee3087802443c3628a5bd9
ssdeep: 3072:HMealRjMJ6aU1M0V5fBWcXPQhHIayp3REhfYqe2l:ilRoAZ5fBWYo5yp3RmYqx
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2018, zorenumim
InternalName: kexixol.exe
FileVersion: 6.2.3.93
ProductVersion: 6.2.3.93
Translation: 0x0449 0x04b1

Win32/Kryptik.GPQX also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.5573
ALYacTrojan.GenericKDZ.53852
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirTool:Win32/CeeInject.6c603806
K7GWTrojan ( 00547b021 )
K7AntiVirusTrojan ( 00547b021 )
ESET-NOD32a variant of Win32/Kryptik.GPQX
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.53852
NANO-AntivirusTrojan.Win32.Dofoil.fnaoeb
ViRobotTrojan.Win32.GandCrab.Gen.B
MicroWorld-eScanTrojan.GenericKDZ.53852
TencentWin32.Trojan-downloader.Dofoil.Agve
Ad-AwareTrojan.GenericKDZ.53852
SophosML/PE-A + Mal/GandCrab-G
ComodoTrojWare.Win32.TrojanDownloader.Dofoil.PH@82bs73
F-SecureTrojan.TR/Crypt.XPACK.Gen
BitDefenderThetaGen:NN.ZexaF.34170.imKfaW2EQJaG
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.7b0e7c40e3f384bf
EmsisoftTrojan.GenericKDZ.53852 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Stealer.aig
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_87%
Antiy-AVLTrojan/Generic.ASMalwS.2A9412E
MicrosoftRansom:Win32/Gandcrab
ArcabitTrojan.Generic.DD25C
GDataTrojan.GenericKDZ.53852
AhnLab-V3Trojan/Win32.Gandcrab.R255352
Acronissuspicious
McAfeeArtemis!7B0E7C40E3F3
MAXmalware (ai score=86)
VBA32BScope.Trojan.Diple
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!z2wm+MTyOL0
IkarusTrojan.Win32.Crypt
MaxSecureRansomeware.CRAB.gen
FortinetW32/Kryptik.GPQM!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.GPQX?

Win32/Kryptik.GPQX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment