Malware

Win32/Kryptik.HNUC information

Malware Removal

The Win32/Kryptik.HNUC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNUC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Divehi
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HNUC?


File Info:

name: 1943E28B3935442EC4E2.mlw
path: /opt/CAPEv2/storage/binaries/d0337586573da11e4382b5190c3284cd3ee0dc39dab2ba0cbc914a79a0b45dce
crc32: A10C7512
md5: 1943e28b3935442ec4e217979a6fc7a4
sha1: 31c406908b8b80f257a80e5a61433bb860ca554a
sha256: d0337586573da11e4382b5190c3284cd3ee0dc39dab2ba0cbc914a79a0b45dce
sha512: 9f8a90a4df1268d72eaa307c8cfac7d3fa604eaf2b4b12ae1b71fe1fbed7cc7b6009440fadd4b7514512659059cfb76d4b71fcb160ef70f7d0b8ed65490bb118
ssdeep: 6144:YHEXs0trsigHwhDdf5ZGx0GwZTmLCt6f611lDPwwwwwwwwwwwwwwwwwwwwwwwwwU:+EXJaigHwhDbZ1G+KLCt6k1l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CE64B3AD98B55B7D43824FC3328BF5585BE93B1D54003F7C841B2E0A1ADA82B5DE25B
sha3_384: 89e8780688c53b54fd75faf091156dffcf78d05377799a872731e57ce2d8526bd063fa7894f53defcb10e2131995ce94
ep_bytes: 8bff558bece876770000e8110000005d
timestamp: 2020-11-27 19:01:48

Version Info:

0: [No Data]

Win32/Kryptik.HNUC also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.81929
FireEyeGeneric.mg.1943e28b3935442e
McAfeePacked-GEE!1943E28B3935
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058c23b1 )
K7GWTrojan ( 0058c23b1 )
CyrenW32/Kryptik.FSC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNUC
BaiduWin32.Trojan.Kryptik.jm
ClamAVWin.Malware.Generic-9917504-0
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderTrojan.GenericKDZ.81929
AvastWin32:DropperX-gen [Drp]
TencentBackdoor.Win32.Tofsee.16000134
Ad-AwareTrojan.GenericKDZ.81929
EmsisoftTrojan.GenericKDZ.81929 (B)
DrWebTrojan.DownLoader44.16575
ZillyaTrojan.Kryptik.Win32.3661793
McAfee-GW-EditionBehavesLike.Win32.Worm.tz
SentinelOneStatic AI – Malicious PE
SophosML/PE-A
APEXMalicious
GDataWin32.Trojan.BSE.1C41Z77
JiangminTrojanSpy.Stealer.lqq
MaxSecureTrojan.Malware.121218.susgen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34FB361
MicrosoftRansom:Win32/StopCrypt.MZB!MTB
AhnLab-V3Infostealer/Win.SmokeLoader.R460106
Acronissuspicious
ALYacTrojan.GenericKDZ.81929
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.GS
RisingMalware.Obscure!1.A3BB (RDMK:cmRtazp4Udj93GC/d6JLescYEQT8)
YandexTrojan.GenKryptik!/KSXgCjQ+JE
IkarusTrojan.Win32.Raccrypt
eGambitUnsafe.AI_Score_70%
FortinetW32/Kryptik.FSC!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Win32/Kryptik.HNUC?

Win32/Kryptik.HNUC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment