Malware

Win32/Kryptik.DEQH information

Malware Removal

The Win32/Kryptik.DEQH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DEQH virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Win32/Kryptik.DEQH?


File Info:

name: 703A07CDA458E3445392.mlw
path: /opt/CAPEv2/storage/binaries/487848eb204530335e8f677b7e071b28adfc8224db08f92de3fd1fc9558a3732
crc32: DC5B8BB5
md5: 703a07cda458e34453920a031aa40b04
sha1: 456e9abe2409cc890be2d619c327a225a44a1cd5
sha256: 487848eb204530335e8f677b7e071b28adfc8224db08f92de3fd1fc9558a3732
sha512: 73d30cd5e9e970a7bbb956c93df07b821a2dd11f0445375720a4cf270678018172f1743e44f5e707edddad6d341944923dd15f90769cb3a8a15de41a876a8b89
ssdeep: 768:CG2zLvkY9NdgLri5IoZSAzcwf3qeevdc9mnYIuC:M/vjNdgLu5IoZSAzcwf3qeevdcInq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF13E662F6D898C5F92712B42D3AED12001BBEAD57788A5E3586761F85B33831437F0B
sha3_384: 2399a713793e714de684e6c61b961c791df629095c055af800a2c0ec33bddec895da51422ed70d506b7f1b4b9b5c3a74
ep_bytes: 64a100000000558bec6aff6860334000
timestamp: 2006-05-07 22:03:43

Version Info:

CompanyName: BraveChan Software
FileDescription: BraveChan Software utility
FileVersion: 1, 0, 3, 5
InternalName: BraveChan Software
LegalCopyright: Copyright (C)2014 BraveChan Software
LegalTrademarks: Copyright (C)2014 BraveChan Software
OriginalFilename: chutility.exe
PrivateBuild:
ProductName: BraveChan Software
ProductVersion: 1, 0, 3, 5
Comments: Copyright (C)2014 BraveChan Software
SpecialBuild: No
Translation: 0x0409 0x04b2

Win32/Kryptik.DEQH also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Ipatre.1
FireEyeGeneric.mg.703a07cda458e344
CAT-QuickHealDownloader.Upatre.14931
ALYacGen:Trojan.Ipatre.1
CylanceUnsafe
K7AntiVirusTrojan ( 004c16241 )
K7GWTrojan ( 004c16241 )
Cybereasonmalicious.da458e
BaiduWin32.Trojan.Kryptik.jc
CyrenW32/Upatre.J.gen!Eldorado
SymantecDownloader.Upatre!gm
ESET-NOD32a variant of Win32/Kryptik.DEQH
APEXMalicious
KasperskyTrojan-Downloader.Win32.Upatre.vxc
BitDefenderGen:Trojan.Ipatre.1
NANO-AntivirusTrojan.Win32.Upatre.dqhfev
AvastFileRepMalware
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Trojan.Ipatre.1
SophosML/PE-A + Troj/Dyreza-ET
ComodoTrojWare.Win32.TrojanDownloader.Upatre.MAUA@5rueuc
DrWebTrojan.Upatre.184
VIPRETrojan.Win32.Upatre.qv (v)
TrendMicroTROJ_UPATRE.TOMB00000005
McAfee-GW-EditionUpatre-FACM!703A07CDA458
EmsisoftGen:Trojan.Ipatre.1 (B)
GDataGen:Trojan.Ipatre.1
JiangminTrojanDownloader.Upatre.py
AviraHEUR/AGEN.1143231
MAXmalware (ai score=89)
ViRobotTrojan.Win32.Agent.32768.KX
MicrosoftTrojanDownloader:Win32/Upatre.AF
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Upatre.R145122
McAfeeUpatre-FACM!703A07CDA458
VBA32BScope.Backdoor.Androm
MalwarebytesTrojan.Upatre
TrendMicro-HouseCallTROJ_UPATRE.TOMB00000005
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazrY8mOVlMCT8Cy4H50C+zPO)
IkarusTrojan-Downloader.Win32.Upatre
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34294.cq0@aOtKJFki
AVGFileRepMalware
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.DEQH?

Win32/Kryptik.DEQH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment