Malware

Win32/Kryptik.HQQL removal tips

Malware Removal

The Win32/Kryptik.HQQL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HQQL virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Georgian
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HQQL?


File Info:

name: A9DF838FE62D09CA6E05.mlw
path: /opt/CAPEv2/storage/binaries/2302988ec86b407c456f941d0938b792c8452604f75471284403c24cc3c616bf
crc32: 29C44AA0
md5: a9df838fe62d09ca6e05838ca816ec38
sha1: be80d3d3dfbdd506d17409cb51e24bbb3d12f54d
sha256: 2302988ec86b407c456f941d0938b792c8452604f75471284403c24cc3c616bf
sha512: 63370f285a7ab79d69c2704aba3e10344b8b42945868abdbcef04dc8e26b620dd4b0b2da877962b9c2e3ac1a566707bac898ace7d5e0943ca4cc285b01fe5fd8
ssdeep: 12288:XFlocvX5zX4HNOQtIXGe4LycsL0kha4e:1lomXNX4tGV8y7faV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F094022238A0C432D9D254705875DB607EBAB9222A344E8737B5177ECF703E299B774E
sha3_384: 9272a22b398c3c449098b92df488acb5cefc3bce160cf2e0158e05650f0aecea0a43a7d8f04bc0a0ea05d1c17263dc69
ep_bytes: e81c420000e978feffff8bff558bec8b
timestamp: 2021-08-09 06:09:15

Version Info:

FileVersions: 9.1.2.1
Copyright: Copyright (C) 2022, somoklos
ProjectVersion: 74.15.66.25

Win32/Kryptik.HQQL also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.91577
FireEyeGeneric.mg.a9df838fe62d09ca
ALYacTrojan.GenericKDZ.91577
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.fe62d0
CyrenW32/Kryptik.HLI.gen!Eldorado
SymantecPacked.Generic.525
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQQL
ClamAVWin.Malware.Azorult-9949206-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKDZ.91577
CynetMalicious (score: 100)
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.FalseSign.Ftgl
Ad-AwareTrojan.GenericKDZ.91577
EmsisoftTrojan.GenericKDZ.91577 (B)
F-SecureTrojan.TR/Crypt.Agent.vpsoe
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
SophosML/PE-A
APEXMalicious
GDataTrojan.GenericKDZ.91577
AviraTR/Crypt.Agent.vpsoe
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D165B9
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R513605
McAfeeArtemis!A9DF838FE62D
VBA32BScope.TrojanDownloader.Smoke
MalwarebytesTrojan.MalPack
IkarusTrojan-Spy.Agent
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HQQL!tr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HQQL?

Win32/Kryptik.HQQL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment