Malware

Win32/Kryptik.HFFQ removal

Malware Removal

The Win32/Kryptik.HFFQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFFQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

How to determine Win32/Kryptik.HFFQ?


File Info:

crc32: 7476A7D8
md5: fbbc305e04802519e31aff0f64b56c98
name: upload_file
sha1: 1a32091a647b810490b82d517af23d3c1438060c
sha256: 97445733427878f5cbfd8b7532834ff54d32a47918767788f6012453832ce0dd
sha512: 851f48ea9ac80ba0e565c77529501fefc9286857a1775ff5e5b467230077350237aa2084a5008374a046705282cbcd3927247f60f590419d7f9272ea7c400881
ssdeep: 12288:22NVqHzevfqCG8pInsjtoXejRnBMm8y3M:22KWfqmpI+oypA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: CHexEditDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: CHexEditDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: CHexEditDemo MFC Application
OriginalFilename: CHexEditDemo.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HFFQ also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.EUFR
FireEyeGeneric.mg.fbbc305e04802519
Qihoo-360Win32/Trojan.653
McAfeeEmotet-FRI!FBBC305E0480
MalwarebytesTrojan.MalPack.TRE
K7AntiVirusTrojan ( 0056b6ba1 )
BitDefenderTrojan.Agent.EUFR
K7GWTrojan ( 0056b6ba1 )
TrendMicroTROJ_GEN.R002C0WGT20
F-ProtW32/Emotet.AOD.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Emotet.ahbz
AlibabaTrojan:Win32/Emotet.4ad815d0
ViRobotTrojan.Win32.Emotet.684032
RisingTrojan.Kryptik!1.C80B (CLASSIC)
Ad-AwareTrojan.Agent.EUFR
SophosTroj/Emotet-CKJ
DrWebTrojan.DownLoader34.9534
Invinceaheuristic
EmsisoftTrojan.Emotet (A)
CyrenW32/Emotet.AOD.gen!Eldorado
FortinetW32/Emotet.FHGO!tr
ArcabitTrojan.Agent.EUFR
ZoneAlarmBackdoor.Win32.Emotet.ahbz
MicrosoftTrojan:Win32/Emotet.PEE!MTB
AhnLab-V3Trojan/Win32.Emotet.R346335
BitDefenderThetaGen:NN.ZexaF.34144.Pq0@a4ViWbkj
ALYacTrojan.Agent.EUFR
MAXmalware (ai score=80)
PandaTrj/Emotet.C
ESET-NOD32a variant of Win32/Kryptik.HFFQ
TrendMicro-HouseCallTROJ_GEN.R002C0WGT20
IkarusTrojan-Banker.Emotet
GDataTrojan.Agent.EUFR
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]

How to remove Win32/Kryptik.HFFQ?

Win32/Kryptik.HFFQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment