Malware

Win32/Kryptik.HHQR removal

Malware Removal

The Win32/Kryptik.HHQR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHQR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

Related domains:

newcoldstart.com
ip-api.com

How to determine Win32/Kryptik.HHQR?


File Info:

crc32: D7918ACF
md5: 5bd6a17341164eb9be5c4149e619aa6a
name: 5BD6A17341164EB9BE5C4149E619AA6A.mlw
sha1: 0b0c4aed5e0216d5601cbec1fdc994bdfa0c5880
sha256: 44ff6d294f2a5bd347385b204d5d6e219ce5e785cf567fb48820b0c4aefac4e1
sha512: d2693547152a6b2d065310b581a391b15c28a1ae1f50341fba9ee3517a99d9bc5397742184d06a7d784837457d5d950babd065e388cbee38ab5941e18b2d67f0
ssdeep: 6144:dqG7QsOQVjAF/MBJpZPcL/J0epQROgCgs9/TroIwKho2ZWhCApjz5LyGCM:dj7zWFkLpZPeJgpO9fYKhoyw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: driseapoges.ots
FileVers: 25.26.361
Copyright: Copyrighz (C) 2020, pipkafug
TranslationUsa: 0x0471 0x011c

Win32/Kryptik.HHQR also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71528
McAfeeTrojan-FSWW!5BD6A1734116
CylanceUnsafe
AegisLabTrojan.Win32.Scrop.b!c
SangforMalware
BitDefenderTrojan.GenericKDZ.71528
Cybereasonmalicious.d5e021
ArcabitTrojan.Generic.D11768
CyrenW32/Kryptik.CNB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHQR
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Dropper.Win32.Scrop.gen
AlibabaTrojan:Win32/Kryptik.95ede57c
RisingTrojan.Kryptik!8.8 (TFE:5:b7J8kLxCpTG)
Ad-AwareTrojan.GenericKDZ.71528
SophosMal/Generic-S
F-SecureTrojan.TR/AD.VidarStealer.XR
TrendMicroTROJ_GEN.R002C0WKO20
McAfee-GW-EditionBehavesLike.Win32.Gupboot.jh
FireEyeGeneric.mg.5bd6a17341164eb9
EmsisoftTrojan.GenericKDZ.71528 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.VidarStealer.XR
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Azorult.FW!MTB
ZoneAlarmHEUR:Trojan-Dropper.Win32.Scrop.gen
GDataTrojan.GenericKDZ.71528
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R356118
Acronissuspicious
ALYacTrojan.GenericKDZ.71528
VBA32Malware-Cryptor.InstallCore.6
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WKO20
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_60%
FortinetW32/GenKryptik.ERHN!tr
WebrootW32.Malware.Gen
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM10.2.7747.Malware.Gen

How to remove Win32/Kryptik.HHQR?

Win32/Kryptik.HHQR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment