Malware

Win32/Kryptik.HHQB malicious file

Malware Removal

The Win32/Kryptik.HHQB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHQB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HHQB?


File Info:

crc32: 3DB56E05
md5: 761e217f02855c7368259f63332d61df
name: 761E217F02855C7368259F63332D61DF.mlw
sha1: a8f7630f3804f9d52da46e18efa0116ff5d4262b
sha256: d896fea673941330bf9b4aca5ad7bd1b5e12d3768bfaea9521c843ac1324c629
sha512: d24886f732a2e3d38e56ff56ea0e2f65eb686af2ace6c76368930505b1efcf2124727b65cbf2d406805ee9e73b074af8d6434e5503f8b14745625e3026a7278c
ssdeep: 3072:+SPVjZoCdJKXF29/phDlPf+1bnW7m4EtkN:LPtZhd0u/phDtm17W7mu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: driseapoges.otb
FileVers: 15.26.361
Copyright: Copyrighz (C) 2020, pipkabog
TranslationUsa: 0x0471 0x0999

Win32/Kryptik.HHQB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71500
FireEyeGeneric.mg.761e217f02855c73
Qihoo-360HEUR/QVM10.1.7BBB.Malware.Gen
McAfeeTrojan-FSWW!761E217F0285
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKDZ.71500
Cybereasonmalicious.f3804f
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan.Win32.Zenpak.gen
RisingTrojan.Generic@ML.100 (RDML:kLwhXKh4OC0zThIRWVvR7w)
Ad-AwareTrojan.GenericKDZ.71500
SophosML/PE-A
F-SecureTrojan.TR/AD.Coroxy.HY
McAfee-GW-EditionBehavesLike.Win32.Generic.dz
EmsisoftTrojan.GenericKDZ.71500 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Coroxy.HY
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Generic.D1174C
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.GenericKDZ.71500
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R356027
Acronissuspicious
ALYacTrojan.GenericKDZ.71500
VBA32Malware-Cryptor.InstallCore.6
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HHQB
FortinetW32/Kryptik.HHPZ!tr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HHQB?

Win32/Kryptik.HHQB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment