Malware

About “Win32:Kryptik-PQT [Adw]” infection

Malware Removal

The Win32:Kryptik-PQT [Adw] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Kryptik-PQT [Adw] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
dill.orangessmoke.xyz
potato.giraffegiraffe.website
a.tomx.xyz

How to determine Win32:Kryptik-PQT [Adw]?


File Info:

crc32: 884137A7
md5: b15f3af7013278f8a0a4e3df1eee36bc
name: B15F3AF7013278F8A0A4E3DF1EEE36BC.mlw
sha1: 48d7fda59b0ec39587861a639dbb7c84ce160fbc
sha256: dc024716091b611fcec6954a96734c8407315ea3816580ce1a5b5073616c818d
sha512: 32fa555eefc381464c2738e253121e0cc24cae53e58b4d0caa79d741f028193e9aa15e739dda32313ccf01a06703a733fe7112ab56f19d87e350e7d71278e8d1
ssdeep: 24576:2+9qzSD5IFxIt94TniL5dRB0LnwFtBSVFZgp:QSD5ayt94mFUytBQF8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32:Kryptik-PQT [Adw] also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053c4231 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17914
CynetMalicious (score: 100)
CAT-QuickHealSwbndlr.Dlhelper.V2
ALYacGen:Heur.Mint.Zamg.1
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.51760
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaAdWare:Win32/StartSurf.1a6fcb0c
K7GWTrojan ( 0053c4231 )
Cybereasonmalicious.701327
CyrenW32/S-afc4d532!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GKQR
APEXMalicious
AvastWin32:Kryptik-PQT [Adw]
Kasperskynot-a-virus:AdWare.Win32.StartSurf.chok
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentMalware.Win32.Gencirc.10cba676
Ad-AwareGen:Heur.Mint.Zamg.1
SophosIStartSurfInstaller (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.DvW@a4ZrRcii
McAfee-GW-EditionBehavesLike.Win32.Downloader.tm
FireEyeGeneric.mg.b15f3af7013278f8
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.daix
AviraTR/Crypt.XPACK.Gen4
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.28056CE
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
GDataGen:Heur.Mint.Zamg.1
AhnLab-V3PUP/Win32.StartSurf.R237693
Acronissuspicious
McAfeePacked-FKC!B15F3AF70132
MAXmalware (ai score=100)
VBA32BScope.Adware.DownloadHelper
MalwarebytesAdware.IStartSurf
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.StartSurf!GFGZaqLWrrw
IkarusPUA.Dlhelper
FortinetW32/GenKryptik.CFOO!tr
AVGWin32:Kryptik-PQT [Adw]
Paloaltogeneric.ml

How to remove Win32:Kryptik-PQT [Adw]?

Win32:Kryptik-PQT [Adw] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment