Malware

Win32/Kryptik.HNXQ removal tips

Malware Removal

The Win32/Kryptik.HNXQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNXQ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Divehi
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HNXQ?


File Info:

name: 984635115BBF9349BF27.mlw
path: /opt/CAPEv2/storage/binaries/14c7cdaa420fa9ee40f8701722107d87aea4e0596f2d38b1d6a703443f25d3ab
crc32: 1BA4B789
md5: 984635115bbf9349bf27f3fc2675d118
sha1: d0d5814e7d0c30528fad55a6f74ce416f0d9c0c8
sha256: 14c7cdaa420fa9ee40f8701722107d87aea4e0596f2d38b1d6a703443f25d3ab
sha512: 8a1a0efd53952cfde2b7ad2164daaad84b74a050f0c8260ff219f5686e943523f8a735e925f19408dbeba928fc6ed78178f1cb5a336e76b2e8652a445981628d
ssdeep: 12288:NDQlh6ipN1J84G4SyhElQeDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDT:Zyh6w1Wyh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106D64C3009B1A6B3D0E590BC776C7F235DFCCFA48AD8977552602AE6502B3E498D85CB
sha3_384: 43a699c1400daf0aefa1d6fdbbaf3b5978b6c0377fdd73368bfa1e7796eaf568d33d9e0a60a2813feb0ea50caafc7e69
ep_bytes: 8bff558bece8f6a70000e8110000005d
timestamp: 2021-01-12 06:24:13

Version Info:

0: [No Data]

Win32/Kryptik.HNXQ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.28789
MicroWorld-eScanTrojan.GenericKDZ.82130
FireEyeGeneric.mg.984635115bbf9349
ALYacTrojan.GenericKDZ.82130
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058cbb51 )
K7GWTrojan ( 0058cbb51 )
Cybereasonmalicious.e7d0c3
CyrenW32/Kryptik.GAL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNXQ
ClamAVWin.Packed.Generic-9917434-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
BitDefenderTrojan.GenericKDZ.82130
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKDZ.82130
EmsisoftTrojan.Crypt (A)
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.rt
SophosML/PE-A + Troj/Krypt-FV
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1LAE7J5
JiangminTrojan.Convagent.sb
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.3503AE6
ArcabitTrojan.Generic.D140D2
MicrosoftTrojan:Win32/Azorult.RT!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Stop.R463103
Acronissuspicious
McAfeePacked-GEE!984635115BBF
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingMalware.Heuristic!ET#78% (RDMK:cmRtazpD05ozjyMYiUuLgtrsO/0r)
YandexTrojan.Kryptik!pWMJaoVMyUw
IkarusTrojan.Win32.Raccrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FPRW!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/Kryptik.HNXQ?

Win32/Kryptik.HNXQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment