Malware

What is “Win32/Kryptik.LSQ”?

Malware Removal

The Win32/Kryptik.LSQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.LSQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.LSQ?


File Info:

name: 8A1246911373380AC734.mlw
path: /opt/CAPEv2/storage/binaries/07da0fab1adae67f428d94492486d05f26f7d6bc1476e73b7ee02aadec38c097
crc32: 8A5008D9
md5: 8a1246911373380ac73404df7f13b8ec
sha1: dbef60699fed585ea1f749017a6f5a4f7bd9275d
sha256: 07da0fab1adae67f428d94492486d05f26f7d6bc1476e73b7ee02aadec38c097
sha512: dd3cae2bb15f1228bf6413c210babde408c6dfb970800268f43b76119e10f604d3f06d60106e08b70fbaaba40fba05660078a0ce9ca474989628772f21fa335e
ssdeep: 196608:x7+hiHXGgRQortxUlX84nrfkCbwLiP9ZT2qB/8zqycBGdW:R+sWLmwG49wiZzB/CqDaW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1763342116473CCE3924F7FFAC1C266D18E69D2236D405091B922F6DEBA8E594FF1AC
sha3_384: 47f7bb643b63f80db9b70e4950514a8c4b8e00054a9389adf2da070d5e79d0a47f8c26f34a3e86485a2401894838b90a
ep_bytes: 558bec83c4d4ff75e0ff75f8ff75f48d
timestamp: 2008-05-18 02:57:44

Version Info:

0: [No Data]

Win32/Kryptik.LSQ also known as:

BkavW32.AIDetect.malware2
LionicHacktool.Win32.ArchSMS.lmoi
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.SMShoax.K
FireEyeGeneric.mg.8a1246911373380a
McAfeeArtemis!8A1246911373
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.700434
SangforTrojan.Win32.Multsarch.Q
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojan:Win32/Multsarch.7f2d9b19
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.113733
BitDefenderThetaGen:NN.ZexaF.34212.@FZ@ayGrRspc
VirITTrojan.Win32.SMSSend.HHA
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.LSQ
TrendMicro-HouseCallMal_Kryptik-3
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderApplication.SMShoax.K
NANO-AntivirusTrojan.Win32.ULPM.cwbwbh
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114bc10a
Ad-AwareApplication.SMShoax.K
EmsisoftApplication.SMShoax.K (B)
ComodoMalware@#jp6071dta1b3
DrWebTrojan.SMSSend.4914
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroMal_Kryptik-3
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
APEXMalicious
GDataApplication.SMShoax.K
JiangminTrojan/Generic.nqtb
eGambitGeneric.Malware
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.14F5959
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Multsarch.Q
CynetMalicious (score: 100)
VBA32Trojan.Zeus.EA.0999
ALYacApplication.SMShoax.K
MAXmalware (ai score=100)
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.GenAsa!Jmdy5Tqx3ko
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Kryptik
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Kryptik.LSQ?

Win32/Kryptik.LSQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment