Malware

Win32/Kryptik.HSQU (file analysis)

Malware Removal

The Win32/Kryptik.HSQU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HSQU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.HSQU?


File Info:

name: 699896DC94A0CB7B3D4E.mlw
path: /opt/CAPEv2/storage/binaries/13db9a63e4f9965839aed81f4629c6b3edf2a562175858c7e52c066e157eda57
crc32: 6A91AF0F
md5: 699896dc94a0cb7b3d4ec8d0b0a2b048
sha1: c6e03cdfdad8d312af7054c4e6cda7b00d037fb4
sha256: 13db9a63e4f9965839aed81f4629c6b3edf2a562175858c7e52c066e157eda57
sha512: d4b250649c758298c0cc464c0fdd9a4209f98fee7565fa9238ab4f137010b3b365516ff15a280987c18d35eea1a5b26723ec673bedae8d729fdaf147e0deca43
ssdeep: 49152:sz8JRWD6q3CaahM8vg4PSM5gu1aPLOHerLMidkP/vfVNIoCm+4TIG3iH:sz8J0DzCRhM8lP5gucPLOuMP/v9Ym+46
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AB5183A9E025592E8DD0BF00A4DFAD5E4670A3AD15529493F4F3CADB8F17A382EC153
sha3_384: f4c978cb393365da7b80b8eb9caae365e27d2ba471839f503b5f77d64a07ac791020f61020868e328b8e42c70c839248
ep_bytes: 558becb8546f0000e8d3801e00566a00
timestamp: 2023-02-16 13:01:17

Version Info:

Comments: Cheap army hostility distort egg
CompanyName: Embox gown
FileDescription: Grudge veteran pawn transport content lounge
FileVersion: 7.2142.1960.0
InternalName: Blow
LegalCopyright: Copyright © Pleasure volunteer volunteer convulsion payment gift
LegalTrademarks: Summary element tissue
OriginalFilename: Punish minute
ProductName: Sympathetic month
ProductVersion: 7.2142.1960.0
Translation: 0x081a 0x081a

Win32/Kryptik.HSQU also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.293524
ALYacGen:Variant.Lazy.293524
VIPREGen:Variant.Lazy.293524
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HSQU
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Injuke.goir
BitDefenderGen:Variant.Lazy.293524
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Lazy.293524 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
Trapminemalicious.moderate.ml.score
FireEyeGen:Variant.Lazy.293524
SophosML/PE-A
GDataGen:Variant.Lazy.293524
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=89)
XcitiumTrojWare.Win32.Injector.IMT@5j9hh2
ArcabitTrojan.Lazy.D47A94
ZoneAlarmTrojan.Win32.Injuke.goir
VBA32BScope.TrojanSpy.Zbot
RisingTrojan.Leonem!8.15E05 (TFE:5:cXDm1r1m2sI)
YandexTrojan.GenAsa!SyceT1P2laA
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaAI:Packer.C5310B141F
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c94a0c
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.HSQU?

Win32/Kryptik.HSQU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment