Malware

Win32/Kryptik.HQYW removal guide

Malware Removal

The Win32/Kryptik.HQYW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HQYW virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Georgian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HQYW?


File Info:

name: 5B5C804847DCE403763D.mlw
path: /opt/CAPEv2/storage/binaries/5404f7e02dc3a8ca1c250e55417741cab2a4c1d1a5061c267afc9f43e69c8a26
crc32: 2BDB3990
md5: 5b5c804847dce403763de0d08453ce6f
sha1: 16749ee4b34f2bb7352c633f2fe3704672d4009c
sha256: 5404f7e02dc3a8ca1c250e55417741cab2a4c1d1a5061c267afc9f43e69c8a26
sha512: a3b41b08f0b53cc20ad799b2109230493ce66228026bba95dcbb65fcf33749c0019314d56cd999dc61038de0f2c6fc66cf4e3832adec4ed7d2db309d9d0b6c1d
ssdeep: 6144:MNG84UpEP64uQPOzkUNfddAahpLJKlOL60tnigabwVfs:MNGXUSP6xQm9dAEbtiB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA94D02175D1D831E5A52D308836CFA12BBFB83666208A4BF7745B5E6E733809A7134F
sha3_384: 7a010830c417cee5402b9115b60e709c5cf87fcb95d46b0e0515fc40ece1bd22248c1b122c2ed0bd67f2db8b97121bb9
ep_bytes: e85e620000e978feffffcccccccccccc
timestamp: 2021-06-04 06:13:17

Version Info:

FileVersions: 98.52.44.24
InternationalName: povgwaoci.iwe
Copyright: Copyright (C) 2022, somoklos
ProjectVersion: 0.32.81.93

Win32/Kryptik.HQYW also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.PWS.Stealer.33898
MicroWorld-eScanTrojan.GenericKDZ.92392
FireEyeGeneric.mg.5b5c804847dce403
CAT-QuickHealRansom.Stop.P5
ALYacTrojan.GenericKDZ.92392
CylanceUnsafe
VIPRETrojan.GenericKDZ.92392
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00598be41 )
K7GWTrojan ( 00598be41 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Ransom.QS.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQYW
APEXMalicious
ClamAVWin.Packed.Tofsee-9951336-0
KasperskyTrojan-PSW.Win32.Tepfer.pszbji
BitDefenderTrojan.GenericKDZ.92392
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Generic@AI.85 (RDML:MKWcQaO9e6NVaQCxczUQ0A)
Ad-AwareTrojan.GenericKDZ.92392
EmsisoftTrojan.Crypt (A)
McAfee-GW-EditionBehavesLike.Win32.Lockbit.gc
Trapminesuspicious.low.ml.score
SophosML/PE-A + Troj/Krypt-RF
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.92392
GoogleDetected
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Raccoon.RD!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Extensions.R523254
Acronissuspicious
McAfeeArtemis!5B5C804847DC
VBA32BScope.Trojan.Denes
MalwarebytesTrojan.MalPack.GS
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.GANP!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Win32/Kryptik.HQYW?

Win32/Kryptik.HQYW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment