Malware

About “Win32/Kryptik.HHZQ” infection

Malware Removal

The Win32/Kryptik.HHZQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHZQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Maori
  • The binary likely contains encrypted or compressed data.

How to determine Win32/Kryptik.HHZQ?


File Info:

crc32: 95872F0F
md5: 4723e4ffd2571987e6d2d0e6b6970364
name: 4723E4FFD2571987E6D2D0E6B6970364.mlw
sha1: bfa823c9d78fe41dc4c3aaaeff1914404b8c37e7
sha256: 80332b3d2a5cdc783aea37a1adfd62ca30f3e270182d4c93b9ad6d01856b3bec
sha512: 693576fa3b1ed59bdb5d635f7b5077db22b31639130c06599f8375703c719214017f7daeb0fcfede8e6c3ac105aa37086031a1c707b882b935dd4b2b7dc63f46
ssdeep: 98304:+6LGAxvNOJ9JH2fUkJmnK0R4audefRpMLTnVUd+v//Sv/:+fAxMTN2cImzud0MLTnVUd+3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVer: 1.5.9.29
FileV: 1.0.2.237
Translations: 0x0126 0x01a4

Win32/Kryptik.HHZQ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35559751
ALYacTrojan.GenericKD.35559751
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
BitDefenderTrojan.GenericKD.35559751
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9d78fe
ArcabitTrojan.Generic.D21E9947
CyrenW32/Kryptik.COL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9802920-0
KasperskyHEUR:Trojan.Win32.Agentb.gen
AlibabaTrojanDropper:Win32/Kryptik.5ed13cfd
Ad-AwareTrojan.GenericKD.35559751
EmsisoftTrojan.GenericKD.35559751 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Siggen11.54361
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.wc
FireEyeGeneric.mg.4723e4ffd2571987
SophosMal/Generic-S
IkarusTrojan.Win32.Ranumbot
WebrootW32.Trojan.TR.Crypt.XPACK.Gen3
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=82)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
GDataTrojan.GenericKD.35559751
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R357205
Acronissuspicious
McAfeeTrojan-FSWW!4723E4FFD257
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HHZQ
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.COL!tr
BitDefenderThetaGen:NN.ZexaF.34670.XtW@aSdOBxlG
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Trojan.160

How to remove Win32/Kryptik.HHZQ?

Win32/Kryptik.HHZQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment