Malware

Win32/Kryptik.HPMQ removal guide

Malware Removal

The Win32/Kryptik.HPMQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HPMQ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Marathi
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Writes a potential ransom message to disk
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • STOP ransomware registry artifacts detected
  • Likely virus infection of existing system binary
  • CAPE detected the STOP malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a known STOP-Djvu ransomware decryption instruction / key file.
  • Creates a known STOP ransomware variant mutex
  • STOP ransomware command line behavior detected
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HPMQ?


File Info:

name: 55615B4C75711299F0DC.mlw
path: /opt/CAPEv2/storage/binaries/66c62beeb3412e54eb935995fe7f67ec2c94135df5aed769561da69bba5ea380
crc32: 769AE635
md5: 55615b4c75711299f0dc89118e07bd9b
sha1: ddc5aec18e63f11211bf08f992d8196326ab8566
sha256: 66c62beeb3412e54eb935995fe7f67ec2c94135df5aed769561da69bba5ea380
sha512: e90ca08c934ea02b5465a4873fe2c293cf8a619f346efa58c3ecc7f5f0b152c1f89d7b37c9caac7d473a8cc21023ae0adad24f1f140ff945f5534427c6074c0a
ssdeep: 12288:2r9XUwCYTtzkoY5HG+A3A+q8+81CFP/qlZba4SGLyboiAS8:eXUwCsk9G+AQpbXZ/qDSpbRAS8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T141051252F6C1C076D2924E34DD34C6B5597BB88A5A301A4FE7A03B7E2E327D01A36367
sha3_384: 32faba731da3430fbe49c41e57c0b286f6d7e45e62d7a180f7aca677535ccab46de0a1f2b640167160692b1e7d5c5131
ep_bytes: e8e6300000e989feffff6a0aff159410
timestamp: 2021-07-10 02:57:03

Version Info:

FileVersion: 49.46.71.23
Copyrighz: Copyright (C) 2022, pozkarte
ProjectVersion: 28.81.74.73

Win32/Kryptik.HPMQ also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
FireEyeGeneric.mg.55615b4c75711299
McAfeeArtemis!55615B4C7571
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPacked.Generic.525
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPMQ
ClamAVWin.Malware.Filerepmalware-9941437-0
KasperskyVHO:Trojan.Win32.Agent.gen
AvastRansomX-gen [Ransom]
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Malicious PE
SophosML/PE-A
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
RisingStealer.Agent!8.C2 (TFE:dGZlOgWtWXL1yKAG+g)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGRansomX-gen [Ransom]
Cybereasonmalicious.18e63f

How to remove Win32/Kryptik.HPMQ?

Win32/Kryptik.HPMQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment