Malware

Win32/Kryptik.BQLE removal

Malware Removal

The Win32/Kryptik.BQLE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BQLE virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io

How to determine Win32/Kryptik.BQLE?


File Info:

crc32: 9EB8883D
md5: ba3ecc6b9a83c5d8dadb1966b3e53a25
name: BA3ECC6B9A83C5D8DADB1966B3E53A25.mlw
sha1: ece2050f78a89af69ec2789bb955b7aff3d8ad27
sha256: 628fdd0454f4cce77fb02a13ecbf1144cd142f2f1c0d342c600b4e77f8be51a3
sha512: ea1478c6e39184b37d4ad9d5d2998ed2fecc2f1f707994ce6b68ddaba4353a777e37b3d67e179be6a2a9a45ff5d16de759a5b627cc4649effa47fcff64437776
ssdeep: 3072:KQFr3uw1i6CJYpaf66rnkfCEqgNhuEGpvENv+TIBKb8Q:PRuwQnmE6AniC7g/GpvENTM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Pestful Helly
InternalName: sequels
FileVersion: 5.1.0.0
CompanyName: Pestful Helly
ProductName: sequels epic bot
ProductVersion: 5.1.0.0
FileDescription: sequels utter
OriginalFilename: sequels.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.BQLE also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.Cerber.1
FireEyeGeneric.mg.ba3ecc6b9a83c5d8
CAT-QuickHealTrojan.Generic
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderTrojan.Ransom.Cerber.1
K7GWTrojan ( 0055dd191 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34590.iq1@aienJpei
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BQLE
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.3a1c469c
NANO-AntivirusTrojan.Win32.Encoder.eviukz
RisingRansom.Cerber!8.3058 (CLOUD)
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Cerber-C
ComodoMalware@#c9op52rq6dg4
F-SecureHeuristic.HEUR/AGEN.1110502
DrWebTrojan.Encoder.4794
ZillyaTrojan.Zerber.Win32.235
McAfee-GW-EditionRansomware-GIX!BA3ECC6B9A83
EmsisoftTrojan.Ransom.Cerber.1 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.Zerber.lp
MaxSecureTrojan.Malware.7164915.susgen
AviraHEUR/AGEN.1110502
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Zerber
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Ransom.Cerber.1
AhnLab-V3Malware/Win32.Generic.C1485314
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.Cerber.1
CynetMalicious (score: 100)
McAfeeRansomware-GIX!BA3ECC6B9A83
VBA32Hoax.Zerber
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TencentMalware.Win32.Gencirc.10be0368
YandexTrojan.GenAsa!aM4F91HpiDc
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Cybereasonmalicious.b9a83c
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBo78A

How to remove Win32/Kryptik.BQLE?

Win32/Kryptik.BQLE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment