Trojan

How to remove “Trojan.Win32.Cryprar.qy”?

Malware Removal

The Trojan.Win32.Cryprar.qy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.qy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.qy?


File Info:

name: 950C5679C67CC1E7D9E9.mlw
path: /opt/CAPEv2/storage/binaries/9d5e5d585c55a924729b0d296b299e8fa047073471743c86dace4f7837d51c47
crc32: 6D863480
md5: 950c5679c67cc1e7d9e90172926d244e
sha1: d4174917c9f0815e3973979b9ed8906c158e418e
sha256: 9d5e5d585c55a924729b0d296b299e8fa047073471743c86dace4f7837d51c47
sha512: 70f38976cddbebae181b7fccca2d7ff7909ace8d80b1eae9f126538d6844fc2f82ac8b9c02fc298ae381da2419221739e3ccda69a6b6ac6495f8e102dcebc97d
ssdeep: 49152:1vlvQYJaYGqL0rpICJ+zOwtws4Bu0x6LIgEVx3OVLBWESUK:1NvJGqoEzPerB7V47BSv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD95235226A6C039D6631831DDEDE7A0A979B9350972494BB7C00CFE6E33AF3C125727
sha3_384: 0747947dad400b6d4b03767a9121670cef637e0ef124aa9f1d746470902262a85d03d91b3583ba39bfe5a6b5d2dec014
ep_bytes: e8df650000e978feffff8bff558bec56
timestamp: 2016-02-03 19:38:25

Version Info:

0: [No Data]

Trojan.Win32.Cryprar.qy also known as:

LionicTrojan.Win32.Cryprar.4!c
MicroWorld-eScanTrojan.GenericKD.47460230
FireEyeTrojan.GenericKD.47460230
McAfeeArtemis!950C5679C67C
SangforTrojan.Win32.Cryprar.ky
K7AntiVirusTrojan ( 00581bcf1 )
AlibabaTrojan:Win32/Cryprar.8d1d62d6
K7GWTrojan ( 00581bcf1 )
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DQ
APEXMalicious
AvastSFX:Runner-C [Bd]
KasperskyTrojan.Win32.Cryprar.qy
BitDefenderTrojan.GenericKD.47460230
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
Ad-AwareTrojan.GenericKD.47460230
EmsisoftTrojan.GenericKD.47460230 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
SophosMal/Generic-S
Paloaltogeneric.ml
AviraTR/Agent.wjqpg
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D2D42F86
ViRobotTrojan.Win32.Z.Agent.1930632
GDataTrojan.GenericKD.47460230
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.47460230
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper.VBS
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0DKL21
AVGSFX:Runner-C [Bd]
PandaTrj/CI.A
MaxSecureTrojan.Malware.121777378.susgen

How to remove Trojan.Win32.Cryprar.qy?

Trojan.Win32.Cryprar.qy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment