Malware

About “Win32/Kryptik.HROQ” infection

Malware Removal

The Win32/Kryptik.HROQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HROQ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Tswana
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.HROQ?


File Info:

name: 4DE16EDA72D7547461EB.mlw
path: /opt/CAPEv2/storage/binaries/dd9809306a89ea9eb3a8ee2dae32c41b4b769b4f12869930531d0bcafab6d4ab
crc32: D3C5B2C8
md5: 4de16eda72d7547461ebfdcc0654e296
sha1: 2f395cb356101c21b7d3823ee8a150481dcd9666
sha256: dd9809306a89ea9eb3a8ee2dae32c41b4b769b4f12869930531d0bcafab6d4ab
sha512: e38637c3be0a12d751c06c3a805424171aebeae1a14f3309a3343bdea6f7c67048e6bf9fea5997b717f320d31d832c8065d025f0fca88d2890aad9cff11ac327
ssdeep: 49152:0GVEiVvUbKzjz+yVoQHF84Ib9a+uqpxOQl3ZU2Lz4qg9x1MNpHe48cMIudSnp9We:0GVEiVDjWQHF8484qpxDzL+DqReO/oSY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F7E53380B697D411F19E32388474BBA4D77EFCB210722196B6A637197B331D22B6178F
sha3_384: 4cf890def16f86511bc5ab2fd345d6dfd8d320a4b206dc7ddd6ab9d705f01bacf586879a662c32992f4997830c709c47
ep_bytes: e85a550000e979feffff8bff51c70164
timestamp: 2021-08-23 02:09:21

Version Info:

FileVersions: 41.72.3.29
InternationalName: povgwaoce.iwe
Copyright: Copyright (C) 2022, somoklos
ProjectsVersion: 85.20.68.60

Win32/Kryptik.HROQ also known as:

LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.63675677
FireEyeGeneric.mg.4de16eda72d75474
McAfeeArtemis!4DE16EDA72D7
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059b2ad1 )
AlibabaMalware:Win32/km_24af8.None
K7GWTrojan ( 0059b2ad1 )
VirITTrojan.Win32.Genus.NBM
CyrenW32/Kryptik.HUW.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HROQ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Packed.gen
BitDefenderTrojan.GenericKD.63675677
AvastWin32:BotX-gen [Trj]
Ad-AwareTrojan.GenericKD.63675677
DrWebTrojan.Packed2.44617
McAfee-GW-EditionBehavesLike.Win32.Lockbit.vc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.63675677 (B)
SentinelOneStatic AI – Suspicious PE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/SmokeLoader.IPH!MTB
GDataWin32.Packed.Kryptik.I3XY9E
GoogleDetected
AhnLab-V3Ransomware/Win.Stop.R534701
Acronissuspicious
MAXmalware (ai score=88)
VBA32BScope.Trojan.AET.281105
TencentWin32.Trojan.Packed.Imnw
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:BotX-gen [Trj]
PandaTrj/Chgt.AD

How to remove Win32/Kryptik.HROQ?

Win32/Kryptik.HROQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment