Malware

Win32/GenKryptik.BHRQ (file analysis)

Malware Removal

The Win32/GenKryptik.BHRQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.BHRQ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Win32/GenKryptik.BHRQ?


File Info:

crc32: 64B8510A
md5: 753226a085aa92f7dedd8521271c39e9
name: 753226A085AA92F7DEDD8521271C39E9.mlw
sha1: b137e48ba32b619695260567c98219cc0914673e
sha256: bada071e95e35a3bd371261a1c4e7a52c4ec54ba3d2a6ad9c7209fc8d9316ecd
sha512: 6a2fa9a67905722de4846436ab3ffdae5b4d71e18b0aa8236f74986e88fad33d1bac83f7ac69ec68001b301da702ae2a9c33083b426598130fb23a7c11b7aa0c
ssdeep: 12288:EvS30brcOfyQjZoZ2Kv5JX0fHIywVVjj2qBWmIFLZnCKDj:Eq30b1fyaoZ2KvEvVOVfVWmWjf
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/GenKryptik.BHRQ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004be4ff1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.12411
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.30541106
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.57696
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004be4ff1 )
Cybereasonmalicious.085aa9
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/GenKryptik.BHRQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nyfs
BitDefenderTrojan.GenericKD.30541106
NANO-AntivirusTrojan.Win32.Panda.evtrmr
MicroWorld-eScanTrojan.GenericKD.30541106
TencentWin32.Trojan.Foreign.Afre
Ad-AwareTrojan.GenericKD.30541106
SophosMal/Generic-S
ComodoMalware@#39w58160l8lf3
BitDefenderThetaGen:NN.ZexaF.34796.GmGfaSg8JXii
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Pluto.hc
FireEyeGeneric.mg.753226a085aa92f7
EmsisoftTrojan.GenericKD.30541106 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.23D31EA
MicrosoftTrojanDropper:Win32/Ropest.A
ArcabitTrojan.Generic.D1D20532
GDataTrojan.GenericKD.30541106
Acronissuspicious
McAfeeGeneric.drg
MAXmalware (ai score=96)
VBA32Trojan-Ransom.Foreign
PandaTrj/GdSda.A
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Foreign.NYFS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Foreign.HwsBEpsA

How to remove Win32/GenKryptik.BHRQ?

Win32/GenKryptik.BHRQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment