Malware

About “Win32/Kryptik.HQLC” infection

Malware Removal

The Win32/Kryptik.HQLC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HQLC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Kannada
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the Tofsee malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HQLC?


File Info:

name: 9A5C980146A0CDE97D8C.mlw
path: /opt/CAPEv2/storage/binaries/9eff12c2074aa3b9c9c7b6cd3a862bc852a7acfeba40b104dc159c41d9fe4932
crc32: C714F81D
md5: 9a5c980146a0cde97d8c3437391268fd
sha1: 5920d0a395c7de46026ccd94db4e7dcd8ed4a720
sha256: 9eff12c2074aa3b9c9c7b6cd3a862bc852a7acfeba40b104dc159c41d9fe4932
sha512: fe68c65590176be2be4ebf1f8643c4a7efdbb2ce5dbec922e63f0302e99f667a1b941756208ef19a830638cbaf45a13b234ad0f721892d1e6cde3af99e4c0eb7
ssdeep: 49152:jaJnVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVN:j
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15CB68C7366A19D8BE1AD2770893A4FF1177EFD4E6864521A2420374E3FB3340996632F
sha3_384: c68a28fdf5f0ffa32cbcb49f638213d24f21ac2842c22771998c903b94ed0240e7af1c112f4d7c3656dd1a006c234d84
ep_bytes: e82f5c0000e989feffffcccccccccccc
timestamp: 2021-02-17 06:32:30

Version Info:

FileVersions: 48.90.12.84
Copyrighz: Copyright (C) 2022, pozkarte
ProjectVersion: 92.4.7.98

Win32/Kryptik.HQLC also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.90858
FireEyeGeneric.mg.9a5c980146a0cde9
ALYacTrojan.GenericKDZ.90858
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3863899
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00516fdf1 )
AlibabaBackdoor:Win32/Tofsee.62b3d185
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.395c7d
CyrenW32/Kryptik.GVX.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQLC
TrendMicro-HouseCallTROJ_GEN.R032C0DHK22
ClamAVWin.Malware.Azorult-9949206-0
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderTrojan.GenericKDZ.90858
NANO-AntivirusTrojan.Win32.Tofsee.jrmnkq
CynetMalicious (score: 100)
AvastWin32:DropperX-gen [Drp]
Ad-AwareTrojan.GenericKDZ.90858
EmsisoftTrojan.GenericKDZ.90858 (B)
DrWebTrojan.Siggen18.37121
VIPRETrojan.GenericKDZ.90858
TrendMicroTROJ_GEN.R032C0DHK22
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
SophosMal/Generic-R + Mal/Agent-AWV
APEXMalicious
JiangminBackdoor.Tofsee.fwc
AviraTR/AD.Tofsee.smpzq
Antiy-AVLTrojan/Generic.ASMalwS.769
MicrosoftTrojan:Win32/Raccooon.RI!MTB
ArcabitTrojan.Generic.D162EA
ZoneAlarmHEUR:Backdoor.Win32.Tofsee.gen
GDataTrojan.GenericKDZ.90858
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R510455
McAfeeGenericRXAA-AA!9A5C980146A0
MAXmalware (ai score=89)
VBA32BScope.Trojan.Formbook
MalwarebytesTrojan.MalPack.GS
RisingRansom.Stop!8.10810 (TFE:5:gb6VIXH6CnD)
IkarusTrojan.Crypter
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HQLF!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HQLC?

Win32/Kryptik.HQLC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment