Malware

Should I remove “Win32/Alyak.F”?

Malware Removal

The Win32/Alyak.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Alyak.F virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Unconventionial binary language: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Alyak.F?


File Info:

name: 478A2E3A51AC8744D577.mlw
path: /opt/CAPEv2/storage/binaries/9e2bce7cecd33eec2674f27a83d096c5b3fd6ca22a027414c843407588c895db
crc32: 5DEEDA2E
md5: 478a2e3a51ac8744d57785555af394ac
sha1: 48a75bb887a4a8c069a25beea5e5fa679c8cd531
sha256: 9e2bce7cecd33eec2674f27a83d096c5b3fd6ca22a027414c843407588c895db
sha512: 901e7f6ef3b01dcd7ac78a5cbe1cff971d6d8a320884433571cf981fe55f8ce8eed4714f8e8d30ce1afa8af832a914a44729389d23d332fedb00c2499fefb47e
ssdeep: 3072:I/TySUyed7ZZetIhprj22IqywjkJdusvQg29OcImz:cQZZVjrIqyw8dViz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0249D1A7A938177D402097097E65ACEBFBD2D3372A24B1FCF80540934B199D6E396F2
sha3_384: b88191e56a423d3874dc32bd1ab10c4670b7d8ddaaef022025aa1139ad59e159aba137bfa1825a3162292d0dec2b3aae
ep_bytes: e9d97d01003727660fb3f88b4500e8bc
timestamp: 2013-07-26 14:12:51

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Internet Explorer Snap-in Extension to Group Policy
FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
InternalName: IEAKSIE.DLL
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
OriginalFilename: IEAKSIE.DLL
ProductName: Microsoft(R) Windows(R) Operating System
ProductVersion: 6.00.2900.5512
Translation: 0x0804 0x04b0

Win32/Alyak.F also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Crypt.lBsS
MicroWorld-eScanGen:Trojan.Heur.mu3@uazibj
ClamAVWin.Malware.Alyak-9781952-0
CAT-QuickHealTrojan.GenericRI.S28992109
McAfeeDownloader-FOK!478A2E3A51AC
MalwarebytesSality.Virus.FileInfector.DDS
VIPREGen:Trojan.Heur.mu3@uazibj
SangforSuspicious.Win32.Save.ins
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/Kanav.3e59d344
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a51ac8
BaiduWin32.Trojan.Scar.b
CyrenW32/Downloader.FB.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Alyak.F
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.hqvm
BitDefenderGen:Trojan.Heur.mu3@uazibj
NANO-AntivirusTrojan.Win32.Scar.chwroc
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
AvastWin32:Agent-APWI [Trj]
TencentTrojan.Win32.Scarsi.a
EmsisoftGen:Trojan.Heur.mu3@uazibj (B)
F-SecureSuspicious:W32/Packed.A
DrWebTrojan.DownLoader9.21397
ZillyaTrojan.Scar.Win32.80203
TrendMicroTROJ_GEN.R002C0DEL23
McAfee-GW-EditionBehavesLike.Win32.Downloader.dt
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.478a2e3a51ac8744
SophosTroj/Kanav-I
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE1.1554CMR
AviraTR/Downloader.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Alyak.B@4q9cjn
ArcabitTrojan.Heur.ED1163E
ZoneAlarmTrojan.Win32.Scar.hqvm
MicrosoftTrojanDownloader:Win32/Kanav.H
GoogleDetected
AhnLab-V3Trojan/Win32.Scar.R76214
BitDefenderThetaAI:Packer.D7F607021A
ALYacGen:Trojan.Heur.mu3@uazibj
VBA32Trojan.Scar
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEL23
RisingDownloader.Kanav!1.9D48 (CLASSIC)
YandexTrojan.Scar!AVfXzXmI43o
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Alyak.B!tr
AVGWin32:Agent-APWI [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Alyak.F?

Win32/Alyak.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment