Malware

Win32:Crypt-QTG [Trj] removal

Malware Removal

The Win32:Crypt-QTG [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Crypt-QTG [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32:Crypt-QTG [Trj]?


File Info:

name: A08E3A29B5F0C9361664.mlw
path: /opt/CAPEv2/storage/binaries/abba82f4f73b9e91f3e2de8923b30e4f3d99d917b7b3ee982d826dfcadd09fce
crc32: 5D2BE4B8
md5: a08e3a29b5f0c9361664985c69b79ce8
sha1: 0adc1f72d70cc66ebf740f5b084d143d552d712a
sha256: abba82f4f73b9e91f3e2de8923b30e4f3d99d917b7b3ee982d826dfcadd09fce
sha512: 18ec0b6903609137c3743ede155af681346983c2988b59f42bb5e975e658d3bf1f9ad55346b3efd12035f30a3b3e752345d6f85bc063de0884e0342aac69eadc
ssdeep: 6144:5t3LPC6GyNKxWzX1WbWtAoO+f+AuOyXxeIHMoJF6:TTCFyNGWJ/W+W04r6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4340107B2F48562D0F6DE77BD7699A85B32FCD39D20A99F07A03A1DAA31B501D1031E
sha3_384: 16fb224404e04296ec9dc6cfd85f54500bd6dd30751bdc88875507b1d555e85f4ae29ccce0b28225cc6bb2ca907247ca
ep_bytes: 557bec6aff68786b400068d43e900064
timestamp: 2014-03-24 16:24:13

Version Info:

0: [No Data]

Win32:Crypt-QTG [Trj] also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.6267
MicroWorld-eScanGen:Heur.Zboter.4
FireEyeGeneric.mg.a08e3a29b5f0c936
CAT-QuickHealTrojan.CeeInject.A4
ALYacGen:Heur.Zboter.4
MalwarebytesSpyware.Zbot.ED
VIPREGen:Heur.Zboter.4
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0055e3991 )
K7GWTrojan ( 0055e3991 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34646.pqZ@aiRjMKmi
CyrenW32/Trojan.CT.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
TrendMicro-HouseCallTROJ_MALKRYP.SM7
ClamAVWin.Dropper.Zeus-9792502-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Zboter.4
NANO-AntivirusTrojan.Win32.MlwGen.drotov
AvastWin32:Crypt-QTG [Trj]
TencentWin32.Trojan.Generic.Simw
Ad-AwareGen:Heur.Zboter.4
SophosML/PE-A + Troj/HkMain-CT
ZillyaTrojan.Zbot.Win32.153130
TrendMicroTROJ_MALKRYP.SM7
McAfee-GW-EditionPWSZbot-FSS!A08E3A29B5F0
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.Zboter.4 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwFH.330C
MicrosoftTrojan:Win32/Bagsu!rfn
GDataGen:Heur.Zboter.4
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransomlock.R116391
Acronissuspicious
McAfeePWSZbot-FSS!A08E3A29B5F0
VBA32TrojanSpy.Zbot
CylanceUnsafe
RisingMalware.Undefined!8.C (TFE:1:DRgKgggukMK)
YandexTrojanSpy.Zbot!nkFtu0Ruf0s
IkarusTrojan.Inject2
FortinetW32/Kryptik.WIF!tr
AVGWin32:Crypt-QTG [Trj]
Cybereasonmalicious.9b5f0c
PandaTrj/Dtcontx.L

How to remove Win32:Crypt-QTG [Trj]?

Win32:Crypt-QTG [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment