Description of Trojan Horse Crypt.AQLW and consequences of its residing on your PC’s

Trojan Horse Crypt.AQLW is hidden from common detecting methods as the infection is hardly coded. On the other hand, its composition reminds that of system executables so that many security solutions simply abandon the infection as they are instructed to treat system items as harmless by default.
Technical Details and screenshots:

  • Full name: Trojan Horse Crypt.AQLW
  • Type: Trojan horse, Virus
  • Risk: EXTREME
  • Trojan Horse Crypt.AQLW Manual removal: Possible
  • Trojan Horse Crypt.AQLW automated removal: Recommended

Signs of being infected with Trojan Horse Crypt.AQLW

There are plenty of after-effects associated with the infection. However, it listens to remote server, thus is flexible to learn new tasks while staying resident to compromised PC.
Slow computer problem, failure of multiple applications to run, connectivity issues, loss of data are common symptoms of the malware. Naturally these cannot serve as a unique identifier.

Trojan Horse Crypt.AQLW automatical removal:

The cleaning solution available below applies alternate extermination routine that offers higher standards of detection and extermination than the one in question.

Trojan Horse Crypt.AQLW Removal Tool

Manual Removal of Trojan Horse Crypt.AQLW:

Manual deletion need to cover all variants of the threat. This results in excessive number of files to check and exterminate and makes the manual way to get rid of Trojan Horse Crypt.AQLW rather impracticable.

Remove Trojan Horse Crypt.AQLW files and dll’s:


Unregister Trojan Horse Crypt.AQLW registry values:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “WarnonBadCertRecving” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop “NoChangingWallPaper” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = ‘/{hq:/s`s:/ogn:/uyu:/dyd:/c`u:/bnl:/ble:/sdf:/lrh:/iul:/iulm:/fhg:/clq:/kqf:/`wh:/lqf:/lqdf:/lnw:/lq2:/l2t:/v`w:/rbs:’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = ’1′
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system “DisableTaskMgr” = ’1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = ‘no’
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main “Use FormSuggest” = ‘yes’
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “Hidden” = ’0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced “ShowSuperHidden” = 0′


