Malware

How to remove “Win32/Kryptik.HQOH”?

Malware Removal

The Win32/Kryptik.HQOH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HQOH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the DanaBot malware family

How to determine Win32/Kryptik.HQOH?


File Info:

name: 5D7B9D8D7A1F39EADD53.mlw
path: /opt/CAPEv2/storage/binaries/4b7fca8bab7abd128cd046055f3035511608a92678e697a516b4dd53c6f17307
crc32: EEDDFF35
md5: 5d7b9d8d7a1f39eadd53c2e77638f613
sha1: 653895ffc489e25ca736394bba36724647464d5b
sha256: 4b7fca8bab7abd128cd046055f3035511608a92678e697a516b4dd53c6f17307
sha512: 90d613e717f405a59ff4ba0488869f1d1a119e6769f1cd63c2fb589f537b1b03c8162ca27443a212e3d09f803d7e93b983bc0d8397862085e12c9ae71b21b6af
ssdeep: 49152:9SQg4UR2IEpXHgS+oiT0vs7bBNHcfTRsPDpndLMr0qKVOb+:9SQgH2lQHHfTkTR6DnLMFFq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0952311BBB18036F1F322F85A7A82A8B52EBF915B6145DF52D57ADD03395E4EC3020B
sha3_384: 47fdc058e73cca199bd3947ec23613d7deb069ac0a0a177c47fc09fb013ddedb9c0a8cb07e782ce58646c036a8d7a9a0
ep_bytes: 8bff558bece816950000e8110000005d
timestamp: 2021-05-30 15:57:54

Version Info:

Translations: 0x0889 0x00aa

Win32/Kryptik.HQOH also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.DownLoader45.12820
MicroWorld-eScanGen:Heur.Mint.Zard.52
FireEyeGeneric.mg.5d7b9d8d7a1f39ea
ALYacGen:Heur.Mint.Zard.52
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005975761 )
K7GWTrojan ( 005975761 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.HJZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQOH
APEXMalicious
ClamAVWin.Packed.Crypterx-9964586-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Heur.Mint.Zard.52
AvastWin32:PWSX-gen [Trj]
Ad-AwareGen:Heur.Mint.Zard.52
EmsisoftGen:Heur.Mint.Zard.52 (B)
VIPREGen:Heur.Mint.Zard.52
TrendMicroRansom.Win32.STOP.SMYXBFX.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.19VUYDS
GoogleDetected
MAXmalware (ai score=80)
ArcabitTrojan.Mint.Zard.52
MicrosoftTrojan:Win32/Azorult.EH!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R512462
McAfeePacked-GEE!5D7B9D8D7A1F
VBA32BScope.TrojanSpy.Stealer
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@AI.91 (RDML:AKBaxU3/xdpwbRVNNYRZuw)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FBYO!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.fc489e
PandaTrj/Genetic.gen

How to remove Win32/Kryptik.HQOH?

Win32/Kryptik.HQOH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment