Malware

Win32/Kryptik.QLX malicious file

Malware Removal

The Win32/Kryptik.QLX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.QLX virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Win32/Kryptik.QLX?


File Info:

name: EE75422A320F1CF69863.mlw
path: /opt/CAPEv2/storage/binaries/1a45385ae367210ffb6c08bbc393746152cb65f3d82f08c6fbc810d91fe782a1
crc32: 31A0C379
md5: ee75422a320f1cf698639b18d1c85d23
sha1: b88231cf5f7701a99661c0f3fb64094ad6e21736
sha256: 1a45385ae367210ffb6c08bbc393746152cb65f3d82f08c6fbc810d91fe782a1
sha512: aec629a601e333d3d1c1477442c440a98aeea6b8283cb598878e4665d858207c2425514bcdb30d586f8179b10f774a4af5b6e444f345a6801bc5cb8a493c7f11
ssdeep: 768:gF75Qu6d+I5m5XzrJCIp3ptMDW5cxsNxUtJqlPs:4aUXQI9wDW5XN6t8E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A103BE8F7C912EF2CF6472716B78CF73D67A038AF9602D3AA728D0C5590A759D520A0C
sha3_384: d0722a3693bf1e843f3545732b16677668ea63df4d85f29b4e9cd0dfb8e58d661882b5ed2371052e9cda0e2badc1496a
ep_bytes: 558becff3570404000ff1530304000ff
timestamp: 2011-08-02 06:55:08

Version Info:

0: [No Data]

Win32/Kryptik.QLX also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen3.2660
MicroWorld-eScanGen:Variant.Kates.2
FireEyeGeneric.mg.ee75422a320f1cf6
CAT-QuickHealTrojanDownloader.Unruy.H
ALYacGen:Variant.Kates.2
CylanceUnsafe
ZillyaTrojan.Cycler.Win32.1319
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00530b9f1 )
K7GWTrojan ( 00530b9f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.EF8290BB1E
VirITTrojan.Win32.Generic.CILH
CyrenW32/Unruy.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.QLX
APEXMalicious
TrendMicro-HouseCallTROJ_FAKEAV.SMFI
ClamAVWin.Trojan.Clicker-4132
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kates.2
NANO-AntivirusTrojan.Win32.Cycler.vpfxt
SUPERAntiSpywareTrojan.Agent/Gen-Replacer
AvastWin32:Kryptik-EIW [Trj]
TencentTrojan.Win32.FakeAV.jf
Ad-AwareGen:Variant.Kates.2
TACHYONTrojan-Clicker/W32.Cycler.39428.F
EmsisoftGen:Variant.Kates.2 (B)
ComodoTrojWare.Win32.Kryptik.QLX@3ysh21
VIPREGen:Variant.Kates.2
TrendMicroTROJ_FAKEAV.SMFI
McAfee-GW-EditionBehavesLike.Win32.VirRansom.nc
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-ZC
IkarusGen.Trojan.Heur
JiangminTrojanClicker.Cycler.bfs
WebrootW32.Cycbot.Gen
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.133
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.A.Clicker.39436
GDataGen:Variant.Kates.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Unruy.39428.E
McAfeeDownloader-BPA.k
MAXmalware (ai score=81)
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.MalPack
RisingTrojan.Agent!1.6741 (CLASSIC)
YandexTrojan.Kryptik!7D9ip5bYAWU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2713018.susgen
FortinetW32/Kryptik.QGA!tr
AVGWin32:Kryptik-EIW [Trj]
Cybereasonmalicious.a320f1
PandaTrj/Genetic.gen

How to remove Win32/Kryptik.QLX?

Win32/Kryptik.QLX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment