Malware

Win32/Kryptik.HBUQ removal instruction

Malware Removal

The Win32/Kryptik.HBUQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBUQ virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Attempts to remove evidence of file being downloaded from the Internet
  • Code injection with CreateRemoteThread in a remote process
  • Creates a copy of itself

How to determine Win32/Kryptik.HBUQ?


File Info:

crc32: 9276F7EB
md5: 374f4f6e37e437d8dd05ab7c4183284f
name: office2010.exe
sha1: 82f019690f3a185cb33b7853417e139556eb76fd
sha256: 3bb621ff5609a79778475be37a2b05d2c38faa0c508ef24ce9e33965dabda791
sha512: 99ad53fd5c0f2eddece5ca2004813c8f9adac8269e673ca8f4c7741713c25e47c42ccfac09fc553ea5ca626b855a0dfd30559cbadff321a04f2744e19feae321
ssdeep: 49152:VPSHZkjOKkuFmy403bd8xGsQMtJIV7rB//M:VPSH/Amaix3/IJr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HBUQ also known as:

MicroWorld-eScanTrojan.GenericKD.33534869
McAfeeArtemis!374F4F6E37E4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Crypt.4!c
K7AntiVirusTrojan ( 0056227f1 )
BitDefenderTrojan.GenericKD.33534869
K7GWTrojan ( 0056227f1 )
F-ProtW32/Wacatac.CD
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.33534869
KasperskyTrojan.MSIL.Crypt.hmwo
AlibabaTrojan:MSIL/Kryptik.53ede30a
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.33534869
EmsisoftTrojan.GenericKD.33534869 (B)
F-SecureTrojan.TR/Crypt.Agent.mgmtx
DrWebTrojan.PWS.Siggen2.44562
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.QZTW-8884
AviraTR/Crypt.Agent.mgmtx
MAXmalware (ai score=86)
Antiy-AVLTrojan/MSIL.Crypt
ArcabitTrojan.Generic.D1FFB395
ZoneAlarmTrojan.MSIL.Crypt.hmwo
MicrosoftTrojan:Win32/Occamy.C
BitDefenderThetaGen:NN.ZexaF.34100.ZPW@aC8c42gi
ALYacTrojan.GenericKD.33534869
TACHYONTrojan/W32.Crypt.1899008
VBA32Trojan.MSIL.Crypt
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBUQ
TrendMicro-HouseCallTROJ_GEN.R023H0CCC20
TencentMsil.Trojan.Crypt.Ljat
SentinelOneDFI – Suspicious PE
FortinetW32/Crypt.HBUQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.23e

How to remove Win32/Kryptik.HBUQ?

Win32/Kryptik.HBUQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment