Trojan

How to remove “Trojan.Win32.Khalesi.lqiq”?

Malware Removal

The Trojan.Win32.Khalesi.lqiq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Khalesi.lqiq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs an hook procedure to monitor for mouse events
  • Attempts to modify proxy settings

How to determine Trojan.Win32.Khalesi.lqiq?


File Info:

name: F6385636B6EF52E6D0B5.mlw
path: /opt/CAPEv2/storage/binaries/3a1ee8a9c1744d62f21a150105c43c3e4ebca9efaf0664b7d75696fc323d52a4
crc32: 92489F34
md5: f6385636b6ef52e6d0b5280da1d9083d
sha1: cc2532eeb805211c4fda267076d2c1a7b3d78487
sha256: 3a1ee8a9c1744d62f21a150105c43c3e4ebca9efaf0664b7d75696fc323d52a4
sha512: 5f049b40a56795908e751f94944a06ec5c07635aeff9b43b7582d4e3fa13dc91cf44ef9328926e2725b645bd8c084c8d92d3b2c1ed698da780267b97ca884274
ssdeep: 12288:1wstciN7Y1LP8uTlcvJi5nGep5krXjSZFE:ustJu1LUS6Ji5nGeQYm
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T116B42393D9030FB0ED2D16768476847B0D2EF8A1CC56A197A2A921C6387D4EF6FC4739
sha3_384: 10033f812a623a08827ce7b976ef7b75824814c14e5b98a51529f930e12db4dae2c6380791a574c80407861657ebb81d
ep_bytes: 53565755488d35153ff8ff488dbe00c0
timestamp: 2021-05-08 03:58:46

Version Info:

CompanyName: dfggdf4
FileDescription: fdgd4
FileVersion: 0.0.0.0
InternalName: sss
LegalCopyright: son
OriginalFilename: sdfh
ProductName: asdgtop
ProductVersion: 0.2.0.0
Translation: 0x0409 0x04b0

Trojan.Win32.Khalesi.lqiq also known as:

LionicTrojan.Win32.Khalesi.4!c
MicroWorld-eScanTrojan.GenericKD.47479453
FireEyeGeneric.mg.f6385636b6ef52e6
McAfeeArtemis!F6385636B6EF
BitDefenderTrojan.GenericKD.47479453
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Khalesi.lqiq
AlibabaTrojan:Win32/Khalesi.8bc501ff
Ad-AwareTrojan.GenericKD.47479453
McAfee-GW-EditionBehavesLike.Win64.CoinMiner.hc
EmsisoftTrojan.GenericKD.47479453 (B)
IkarusTrojan.Khalesi
GDataTrojan.GenericKD.47479453
JiangminTrojan.Khalesi.asgi
MaxSecureTrojan.Malware.300983.susgen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.337895E
ArcabitTrojan.Generic.D2D47A9D
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4590820
ALYacTrojan.GenericKD.47479453
TrendMicro-HouseCallTROJ_GEN.R002H07KQ21
TencentMalware.Win32.Gencirc.11ca553c
SentinelOneStatic AI – Suspicious PE
FortinetMalicious_Behavior.SB
AVGFileRepMalware
AvastFileRepMalware

How to remove Trojan.Win32.Khalesi.lqiq?

Trojan.Win32.Khalesi.lqiq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment