Malware

Win32/Kryptik.LFQ removal tips

Malware Removal

The Win32/Kryptik.LFQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.LFQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

How to determine Win32/Kryptik.LFQ?


File Info:

name: E3EA1AE54FE177A123A4.mlw
path: /opt/CAPEv2/storage/binaries/9ca61c18c2327eae69c350d516482441ea0fc7531bbff16c78e382ff01db7a44
crc32: 9FFCCBD7
md5: e3ea1ae54fe177a123a4ea9095ac7e1f
sha1: 4475b2aae6580f12c6e65916646957d5e859a3cc
sha256: 9ca61c18c2327eae69c350d516482441ea0fc7531bbff16c78e382ff01db7a44
sha512: cb94d3c8c6919d92bbbb4abf7ad91e5673399199bae7a05c0b29679acd5dfabd3f29b095022e172414654b232ec92c55887abe4a8638c1ea41131605c79d501f
ssdeep: 12288:LQ55v3NvXyOqmTQk/PLBQepGg1qDxzy3ve7W+/Xt3a:c5VxXyOqmT5XWZGG7xXc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17BA412BAA711CD3AC0CD4772E5471B69BA30335AD2EA030D9341DE347AB2F69F749A11
sha3_384: f80eb928633c2e03a452df11953eb24ffd12cd2a5cfba1e00d101d11b7e08570c7ee604756497bf5578f286b87cd5846
ep_bytes: 03c8558bf7f7d18bf18bec41f7d683c4
timestamp: 2008-03-02 18:34:04

Version Info:

0: [No Data]

Win32/Kryptik.LFQ also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e3ea1ae54fe177a1
ALYacGen:Variant.Razy.50537
MalwarebytesMalware.AI.1553884152
VIPREPacked.Win32.PWSZbot.gen (v)
SangforRansom.Win32.Gimemo.ub
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Razy.50537
K7GWTrojan ( 0055dd191 )
K7AntiVirusTrojan ( 0055dd191 )
VirITTrojan.Win32.Winlock.EME
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LFQ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Gimemo.ub
AlibabaRansom:Win32/Gimemo.4e35121a
NANO-AntivirusTrojan.Win32.PornoBlocker.tlsyy
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Variant.Razy.50537
RisingRansom.Gimemo!8.306 (CLOUD)
Ad-AwareGen:Variant.Razy.50537
ComodoMalware@#eo4wm0jfya6t
DrWebTrojan.Winlock.3020
ZillyaTrojan.Gimemo.Win32.9179
EmsisoftGen:Variant.Razy.50537 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gimemo.nr
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.1885F68
MicrosoftRansom:Win32/LockScreen.AO
GridinsoftRansom.Win32.Zbot.sa
ZoneAlarmTrojan-Ransom.Win32.Gimemo.ub
GDataGen:Variant.Razy.50537
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
McAfeeArtemis!E3EA1AE54FE1
VBA32Trojan.Zeus.EA.0999
CylanceUnsafe
PandaGeneric Malware
TrendMicro-HouseCallMal_Kryptik-3
TencentWin32.Trojan.Gimemo.Alsk
YandexTrojan.GenAsa!yKF/KqyakQk
IkarusTrojan-Ransom.Gimemo
FortinetW32/Kryptik.NAS!tr
BitDefenderThetaAI:Packer.7B3C04861F
AVGWin32:Kryptik-AHL [Trj]
Cybereasonmalicious.54fe17
AvastWin32:Kryptik-AHL [Trj]
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Kryptik.LFQ?

Win32/Kryptik.LFQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment