Malware

Win32/Kryptik.HNQU information

Malware Removal

The Win32/Kryptik.HNQU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNQU virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • CAPE detected the Sakula malware family
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HNQU?


File Info:

name: 98F6F6E8C3D973A26AC3.mlw
path: /opt/CAPEv2/storage/binaries/411dd9ac47e4cd0d5404c8ccc7fd8b1443156b43c29e2102757a4c84e259ee0d
crc32: D9B87DF8
md5: 98f6f6e8c3d973a26ac3382f7d1ea3a6
sha1: b35898b087eee836843b499bc55d97612c0a8cb6
sha256: 411dd9ac47e4cd0d5404c8ccc7fd8b1443156b43c29e2102757a4c84e259ee0d
sha512: ea1d2996d44b694429646b8c74402354120853e64d471e00a0216274e0c726843c9fe47d47062553e64c5b663586660f56828364eca481eb5c884b6c0ab17e7e
ssdeep: 49152:R9FLcpE0VDtGxEJIH3IgF7TQHHHHnkYPajJhiTWeOaIr7TsP68cRCTrOyEzwVX1T:F0E0ltGxSSbFHCSJU8gl06T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16A66AF5EF12004B0E477F1BA268D132AEB75F8402715A7CF1368A6D76F136E06A3D396
sha3_384: 38afb44aeed61aa104109905139eb3700750db9603bade8f45a6728df1e12a7ff6843b3e3fc2f15c0fa0272687148449
ep_bytes: 09f8ff1567fb6900e96f130000cca120
timestamp: 2021-12-11 02:34:16

Version Info:

FileVersion: 7, 3, 9, 1
CompanyName: Darklings
InternalName: Cajolement
Articular: Unforgiver
Improving: Arriswise
Unaghast: Colla
Periodontoclasia: Ontogenal
Unfeignedly: Counterimpulse
Serpentinize: Palamitism
Nubilum: Cnidarian
Oinomania: Ansel
Repercussion: Regardance
Samaritanism: Thumbscrew
Quoter: Fruitling
Chunner: Refulgent
Beshake: Unmisled
Albuminose: Tetrarchic
Retroserrulate: Pseudomorula
Daniglacial: Hassock
Irreflection: Thiobismuthite
Classically: Postclavicula
Pridian: Dewlapped
Unrehearsable: Nonius
Jeewhillikens: Hemachate
Abradant: Dynamitic
Teleplasm: Friendliwise
Monorail: Vagaristic
Ophicalcite: Entombment
Unknightlike: Pelmet
Leucocholy: Spotteldy
Grating: Bacteriologically
Heterocaseose: Kaliophilite
Abominably: Abthainry
Educative: Pachydermial
Ferrogoslarite: Protectorless
Sporophoric: Incomprehensibility
Zoons: Untopographical
Talayot: Neoblastic
Immethodically: Unicameralism
Balanoposthitis: Unshriven
Silker: Unreturnable
Readd: Pusslike
Megalography: Verticillium
Balneological: Overharshly
Hyoscyamine: Slaglessness
Tamandua: Scumlike
Glazed: Sortilege
Petropharyngeal: Recure
Vulneration: Consectary
Arytenoidal: Paranucleus
Excogitator: Abominably
Cumuli: Maithili
Rapping: Auditorship
Anfractuose: Semilune
Delectableness: Ratiocinatory
Fluviatile: Automatize
Belated: Pedaler
Alleviatory: Titanofluoride
Carapine: Prankish
Unblemishing: Carene
Beaminess: Callosal
Deconsideration: Dingleberry
Gonochorismus: Overlordship
PrivateBuild: Digonous
Translation: 0x0409 0x04e4

Win32/Kryptik.HNQU also known as:

LionicTrojan.Win32.Razy.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.4130
MicroWorld-eScanGen:Variant.Razy.670296
ALYacGen:Variant.Razy.670296
CylanceUnsafe
K7AntiVirusTrojan ( 0058bb951 )
AlibabaTrojan:Win32/SelfDel.8a3a7fa6
K7GWTrojan ( 0058bb951 )
Cybereasonmalicious.8c3d97
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNQU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.SelfDel.hwac
BitDefenderGen:Variant.Razy.670296
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Selfdel.Hxgg
Ad-AwareGen:Variant.Razy.670296
EmsisoftGen:Variant.Razy.670296 (B)
VIPRETrojan.Compcert.101713 (fs)
TrendMicroTROJ_GEN.R002C0RLB21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.98f6f6e8c3d973a2
SophosMal/EncPk-MP
IkarusTrojan.SuspectCRC
GDataGen:Variant.Razy.670296
WebrootW32.Malware.Gen
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Razy.DA3A58
ViRobotTrojan.Win32.Z.Razy.6887632
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C4837579
Acronissuspicious
McAfeeArtemis!98F6F6E8C3D9
MAXmalware (ai score=88)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R002C0RLB21
RisingTrojan.Generic@ML.85 (RDMK:pqdlL5VasZszFNQ2hRsmvw)
eGambitPE.Heur.InvalidSig
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Kryptik.HNQU?

Win32/Kryptik.HNQU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment