Malware

Win32/GenKryptik.ERLQ removal

Malware Removal

The Win32/GenKryptik.ERLQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.ERLQ virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/GenKryptik.ERLQ?


File Info:

crc32: 9E833DF5
md5: a505f083f07f702b869cdd0d499884b7
name: A505F083F07F702B869CDD0D499884B7.mlw
sha1: 0ebec0bac3fa97928904c82e0c7e4ff8a4bcc24f
sha256: 91882c7d9b8979e29c56fd9b3b76b84cbc5347bd3da19eb9044e7d13c1ac071d
sha512: 214c011ad6b9c8acf083ec41883c38929721699d67325e2ed690c09fc7917e89ef03eb30c1aadb555b46145b75555ea31f46ca5da3cbed52a5610bf54baa8ac4
ssdeep: 12288:WVd11fheE9zHDefVEmRnG2BaVfqMVfV2wNUGUJdf+xnxsxPxQymAXVE:WbVHDefVEenG2afqMVfV26UGUJdfG4E
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: xa9 Quick Heal Technologies Ltd. All rights reserved.
InternalName: onlinent.exe
FileVersion: 11.1.0.11
CompanyName: Quick Heal Technologies Ltd.
ProductName: Quick Heal AntiVirus
ProductVersion: 18.00
FileDescription: Online Protection
OriginalFilename: onlinent.exe
Translation: 0x0409 0x04b0

Win32/GenKryptik.ERLQ also known as:

K7AntiVirusTrojan ( 0009162c1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Spy.18178
CynetMalicious (score: 85)
ALYacGen:Variant.Bulz.59362
CylanceUnsafe
ZillyaDropper.NetTraveler.Win32.4
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojanDownloader:Win32/NetTraveler.df96f08c
K7GWTrojan ( 0009162c1 )
Cybereasonmalicious.ac3fa9
TrendMicroTROJ_GEN.R002C0DHO20
SymantecTrojan.Travnet
ESET-NOD32a variant of Win32/GenKryptik.ERLQ
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan-Dropper.Win32.NetTraveler.u
BitDefenderGen:Variant.Bulz.59362
MicroWorld-eScanGen:Variant.Bulz.59362
TencentWin32.Trojan-dropper.Nettraveler.Ljjp
Ad-AwareGen:Variant.Bulz.59362
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Agent.ujhie
BitDefenderThetaGen:NN.ZexaF.34196.@K0@auKxoSf
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.a505f083f07f702b
SophosMal/Generic-S
WebrootW32.Trojan.Travnet
AviraTR/Agent.ujhie
Antiy-AVLTrojan[Dropper]/Win32.NetTraveler
MicrosoftTrojanDownloader:Win32/Travnet.B
ArcabitTrojan.Bulz.DE7E2
AegisLabTrojan.Win32.Bulz.4!c
ZoneAlarmTrojan-Dropper.Win32.NetTraveler.u
GDataGen:Variant.Bulz.59362
McAfeeArtemis!A505F083F07F
MAXmalware (ai score=88)
VBA32Backdoor.Spy
MalwarebytesBackdoor.Bot
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DHO20
RisingDownloader.TravNet!8.D97A (TFE:5:SkmslYmEhBK)
IkarusTrojan.Win32.Agent
FortinetW32/Agent.PIL!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.851

How to remove Win32/GenKryptik.ERLQ?

Win32/GenKryptik.ERLQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment