Malware

Win32/Kryptik.HQPX (file analysis)

Malware Removal

The Win32/Kryptik.HQPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HQPX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Georgian
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.HQPX?


File Info:

name: E11BA9FED39F536091E2.mlw
path: /opt/CAPEv2/storage/binaries/5e90991b875ba7b9e3d16853c8e485e73123381fa21520e6a5045b03a4b39b3c
crc32: 5DEC0565
md5: e11ba9fed39f536091e24c8fdc8b23e7
sha1: 0b1b38d9782155cd23803381ab87fe8f43938db8
sha256: 5e90991b875ba7b9e3d16853c8e485e73123381fa21520e6a5045b03a4b39b3c
sha512: aef31a265a0ebc94a7bf3b342070295de211faec67179396bdb4bfd574f6a5a13721de64da0214c91f578f99093a1993f799f160b8a81c6b19a3d05d9f81e01d
ssdeep: 3072:5zXklH/7Y2/L8Hcdr2oPi7uNKqFROlRcXXsydd+Ycxq:hmLKcJag3TOXcXuYi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18154E012BA83F472C4D544709475CBF46ABF9430176006973B6B2A6E6F703E2967A38F
sha3_384: 2848fb97cb1c512902b65dccc3453071f950f78e2e0abe367b2c0a556294d7e146505c3833f5e272291d11577780aa2e
ep_bytes: e812470000e979feffff8325888fb802
timestamp: 2022-01-04 03:00:43

Version Info:

FileVersions: 9.1.2.1
Copyright: Copyright (C) 2022, soboklos
ProjectVersion: 74.15.66.75

Win32/Kryptik.HQPX also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
AVGWin32:DropperX-gen [Drp]
tehtrisGeneric.Malware
DrWebTrojan.DownLoader45.14802
MicroWorld-eScanGen:Heur.Mint.Zard.52
FireEyeGeneric.mg.e11ba9fed39f5360
CAT-QuickHealTrojan.GenericRI.S28527076
SkyhighBehavesLike.Win32.HWorld.dt
McAfeePacked-GEE!E11BA9FED39F
MalwarebytesTrojan.MalPack
ZillyaTrojan.Kryptik.Win32.3892753
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00597a511 )
AlibabaRansom:Win32/StopCrypt.5dc2092b
K7GWTrojan ( 00597a511 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQPX
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Azorult-9949206-0
KasperskyTrojan.Win32.Agent.xaqkzv
BitDefenderGen:Heur.Mint.Zard.52
NANO-AntivirusTrojan.Win32.Kryptik.jrzipn
RisingStealer.Agent!8.C2 (TFE:5:z3sd95McWsV)
EmsisoftGen:Heur.Mint.Zard.52 (B)
F-SecureHeuristic.HEUR/AGEN.1318586
VIPREGen:Heur.Mint.Zard.52
TrendMicroRansom_StopCrypt.R002C0DB624
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.edyq
GoogleDetected
AviraHEUR/AGEN.1318586
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Sabsik
KingsoftWin32.Trojan.Agent.xaqkzv
MicrosoftRansom:Win32/StopCrypt.SLI!MTB
ArcabitTrojan.Mint.Zard.52
ZoneAlarmTrojan.Win32.Agent.xaqkzv
GDataGen:Heur.Mint.Zard.52
VaristW32/Kryptik.HLI.gen!Eldorado
AhnLab-V3Packed/Win.GEE.R513225
Acronissuspicious
VBA32TrojanDownloader.Smoke
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_StopCrypt.R002C0DB624
TencentTrojan.Win32.Obfuscated.gen
YandexTrojan.Kryptik!363rJSlog8s
IkarusTrojan-Ransom.Stop
MaxSecureTrojan.Malware.187354749.susgen
FortinetW32/Packed.GDT!tr
Cybereasonmalicious.ed39f5
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.Agent.3bd89316

How to remove Win32/Kryptik.HQPX?

Win32/Kryptik.HQPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment