Malware

Should I remove “Win32/Kryptik.GQWT”?

Malware Removal

The Win32/Kryptik.GQWT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GQWT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to identify installed AV products by registry key

Related domains:

8.portgofrost.com
3.portgofrost.com

How to determine Win32/Kryptik.GQWT?


File Info:

crc32: A3376E77
md5: 530877091a93d8cc6c2d976ac5e6667c
name: 530877091A93D8CC6C2D976AC5E6667C.mlw
sha1: 1f6eaa8b5fe885f35f49c35ae26c8ab9e84559da
sha256: a7c4541e79bc02dbef77f0745de6884e9959328d6e769bc39d48fdf177450e1b
sha512: af3293897e7302e6c23fc8642c9c946374a1a8b674c52d96a23e2fd60485349cc99e9ab23562936db468b8560dd30dcaffb5b1e13869ae30d538b544f408b72c
ssdeep: 3072:9gRzAdueZZ/NajGxHvTcLPkawGoNj+Gb+PgD:9g+dueZ1NCkb5GoNy2+PQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Kryptik.GQWT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00549d611 )
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Mint.Jamg.C
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 00549d611 )
Cybereasonmalicious.91a93d
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GQWT
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Chapak.ckfl
BitDefenderTrojan.Mint.Jamg.C
NANO-AntivirusTrojan.Win32.Chapak.fnztxs
MicroWorld-eScanTrojan.Mint.Jamg.C
TencentWin32.Trojan.Chapak.Srwy
Ad-AwareTrojan.Mint.Jamg.C
SophosML/PE-A + Mal/GandCrab-G
ComodoTrojWare.Win32.Propagate.PD@8dtyuh
BitDefenderThetaGen:NN.ZexaF.34058.hmGfaGhKZSaG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.530877091a93d8cc
EmsisoftTrojan.Mint.Jamg.C (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Chapak.fyj
AviraHEUR/AGEN.1119074
Antiy-AVLTrojan/Generic.ASMalwS.2ADD3E4
MicrosoftTrojan:Win32/Dofoil
ArcabitTrojan.Mint.Jamg.C
GDataTrojan.Mint.Jamg.C
AhnLab-V3Trojan/Win32.RansomCrypt.R258745
Acronissuspicious
McAfeeArtemis!530877091A93
MAXmalware (ai score=100)
VBA32BScope.Trojan.Diple
MalwarebytesRansom.GandCrab
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B677 (CLASSIC)
YandexTrojan.Chapak!LUaK+d490AQ
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GQVU!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDownloader.Dofoil.HwsBEpsA

How to remove Win32/Kryptik.GQWT?

Win32/Kryptik.GQWT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment