Malware

Win32/Kryptik.ALQL removal

Malware Removal

The Win32/Kryptik.ALQL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ALQL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.ALQL?


File Info:

name: 1BA115AE4B718B85F36F.mlw
path: /opt/CAPEv2/storage/binaries/7281797628dd47cc17bac74052e1323e5305f27cd2642180e150a89193623784
crc32: A38A595E
md5: 1ba115ae4b718b85f36fcaaf696c1032
sha1: 24d4ff04af964b61c8e6b532127d830f909f71d1
sha256: 7281797628dd47cc17bac74052e1323e5305f27cd2642180e150a89193623784
sha512: c52e6bd503d76f33f8e1875109a7a8e9295db2c91ad22f72591a91520bbca4039d77a167f84f03decef2ca64afa177ec1f6379bf3117b0bd11d9bfe9e444f512
ssdeep: 6144:QmeWDVbOdRoLGpFMBbKGlgJE2/FjDpvI8bOtX:Q8bOboLegW0gS2N3GIa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F634F114BA824977C8F582F9D4FF4E596EA62848177444C397D02F8A6EF41C1FE3A22D
sha3_384: 4bb827d63bbed067003401f5a6b2413218b22f8dc6bc27f5ea58683882cf2e1394823f6206c918d42bd47fdcff2f6d99
ep_bytes: 558bec6aff68a8e44000681c58400064
timestamp: 2012-09-06 22:28:54

Version Info:

0: [No Data]

Win32/Kryptik.ALQL also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.1392
ALYacGen:Variant.Symmi.1392
CylanceUnsafe
VIPRETrojan.Win32.Kuluoz.f (v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Bulta.f445c751
K7GWTrojan ( 0040f0751 )
K7AntiVirusTrojan ( 0040f0751 )
VirITTrojan.Win32.Panda.DMC
CyrenW32/S-0526d851!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ALQL
APEXMalicious
AvastWin32:Citadel-T [Trj]
BitDefenderGen:Variant.Symmi.1392
NANO-AntivirusTrojan.Win32.MlwGen.bdbmsq
TencentMalware.Win32.Gencirc.114c5528
TACHYONTrojan/W32.ZBot.237568.E
SophosMal/Generic-R + Mal/Weelsof-C
ComodoMalware@#11ktfoxf5ipkg
DrWebTrojan.PWS.Panda.2342
ZillyaTrojan.Kryptik.Win32.282778
TrendMicroBackdoor.Win32.RAMNIT.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Symmi.1392 (B)
JiangminTrojan/Generic.amata
WebrootW32.Malware.Gen
AviraTR/Crypt.ZPACK.Gen7
ArcabitTrojan.Symmi.D570
MicrosoftPWS:Win32/Zbot!CI
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=100)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallBackdoor.Win32.RAMNIT.SMA
RisingVirus.Ramnit!8.4 (CLOUD)
YandexTrojan.Kryptik!2QNpbeZrvlA
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.GAI!tr
BitDefenderThetaGen:NN.ZexaF.34212.oqW@aSo1Ckci
AVGWin32:Citadel-T [Trj]
PandaGeneric Malware

How to remove Win32/Kryptik.ALQL?

Win32/Kryptik.ALQL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment