Malware

How to remove “Win32/Kryptik.CQBL”?

Malware Removal

The Win32/Kryptik.CQBL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.CQBL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Win32/Kryptik.CQBL?


File Info:

name: 327D5F01E3C6B9528D79.mlw
path: /opt/CAPEv2/storage/binaries/e6d1d910b3e6c1c537c1db250d647a9d9f274eed77d53d2ba379c923f0a3405f
crc32: FCE65D6F
md5: 327d5f01e3c6b9528d7909e76690bbe2
sha1: 0bc7d701617d12ac73b22b0de4d5294b8bc207b7
sha256: e6d1d910b3e6c1c537c1db250d647a9d9f274eed77d53d2ba379c923f0a3405f
sha512: 6a4f7877c0ee1483e7b45027654fa2d57a717b152a65981b63a62584af37681e7169a15c961825347258a4125b250b5406303fd7b744e657130fed45bde20ee4
ssdeep: 3072:M6oo7qDltcnvp4nUDu7F4TmMRFUsPLHwQhjHfxmV2VX9Sb:M69ODTBx8BHnz8EV2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148F3AE1076E0C036E22325B589F2C3B54A6678754B61AD8F3FCA06B95F385E2E72431F
sha3_384: 68268044dc3a3774bd1cbb7f718c706936ae46f8ca2c43b63a77789c2077f5665ca2f32b2385f05669690b4f145c071a
ep_bytes: e8462b0000e989feffff8bff558bec81
timestamp: 2014-11-12 05:12:32

Version Info:

0: [No Data]

Win32/Kryptik.CQBL also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Ranapama.1
FireEyeGeneric.mg.327d5f01e3c6b952
CAT-QuickHealTrojanDownloader.Kuluoz.O3
ALYacGen:Variant.Ranapama.1
MalwarebytesTrojan.Email.FakeDoc
VIPREGen:Variant.Ranapama.1
SangforTrojan.Win32.Save.a
K7AntiVirusNetWorm ( 0040f9511 )
BitDefenderGen:Variant.Ranapama.1
K7GWNetWorm ( 0040f9511 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34698.kmW@aioLWWmi
VirITTrojan.Win32.Crypt3.BEFD
CyrenW32/Trojan.BAYS-2523
SymantecTrojan.Asprox.B
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.CQBL
BaiduWin32.Trojan.Kryptik.hu
APEXMalicious
ClamAVWin.Malware.Kuluoz-9886290-0
KasperskyTrojan.Win32.Inject.sbea
NANO-AntivirusTrojan.Win32.Kuluoz.diqsdh
CynetMalicious (score: 100)
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
Ad-AwareGen:Variant.Ranapama.1
EmsisoftGen:Variant.Ranapama.1 (B)
ComodoTrojWare.Win32.Spy.Zbot.AOT@5hj40k
DrWebBackDoor.Kuluoz.4
ZillyaTrojan.Inject.Win32.118193
TrendMicroBKDR_KULUOZ.SM19
McAfee-GW-EditionPacked-BZ!327D5F01E3C6
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Weelsof-JC
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Inject.aval
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.77
KingsoftWin32.Troj.Inject.sb.(kcloud)
MicrosoftTrojanDownloader:Win32/Kuluoz
SUPERAntiSpywareTrojan.Agent/Gen-FakeDoc
GDataGen:Variant.Ranapama.1
GoogleDetected
AhnLab-V3Trojan/Win32.Kuluoz.R124733
McAfeePacked-BZ!327D5F01E3C6
TACHYONTrojan/W32.Inject.172032.AB
VBA32BScope.Trojan-Dropper.8612
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_KULUOZ.SM19
TencentTrojan.Win32.Inject.sbeaa
YandexTrojan.Inject!OskdsJ82M5k
IkarusTrojan.Win32.Inject
FortinetW32/Kryptik.CQBL!tr
AVGWin32:Malware-gen
Cybereasonmalicious.1e3c6b
AvastWin32:Malware-gen

How to remove Win32/Kryptik.CQBL?

Win32/Kryptik.CQBL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment