Malware

Heur.Krypt.12 information

Malware Removal

The Heur.Krypt.12 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Krypt.12 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
forces.ru-lola.ru

How to determine Heur.Krypt.12?


File Info:

crc32: 4F6201F2
md5: c6e43161858d5b6c22190db85b021396
name: 1415035053_dsauto.exe
sha1: 2ab6f388e51409ba25156042577be2dd5bf30692
sha256: c29c40f5b24b101f701b297031a89bb0e4a86ecd1e23df3af2118df0cb1b23c5
sha512: 5f16cc9664bde8887fd00512a20eb58c7db7229c0a349dc3e3ae52a2761a4224fdb3b1954fc07b38749b2e1abf4d89aa626b259a155d2911c54310f314178333
ssdeep: 12288:aK6eub7IUa4MXyFb4sPVqkjxoVsa+mMPFKEK:4eufpaZXkb4mEkloVsa7CFnK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1996-2002 Install - Software Corporation
ProductTitle: Update Pack 2
InternalName: Install -
FileVersion: 6.0.6.240
CompanyName: Install - Software Corporation
ProductName: Enterprise
ProductVersion: 6.0
FileDescription: Install - 32 Development Environment
OriginalFilename: Install -
Translation: 0x0409 0x04e4

Heur.Krypt.12 also known as:

BkavHW32.Packed.
DrWebTrojan.LoadMoney.336
MicroWorld-eScanGen:Heur.Krypt.12
FireEyeGeneric.mg.c6e43161858d5b6c
CAT-QuickHealTrojan.Sisproc.A6
McAfeePacked-CQ
CylanceUnsafe
ZillyaAdware.LoadMoneyGen.Win32.7
AegisLabTrojan.Win32.Generic.lson
SangforMalware
K7AntiVirusAdware ( 004b87be1 )
BitDefenderGen:Heur.Krypt.12
K7GWAdware ( 004b87be1 )
Cybereasonmalicious.1858d5
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaCO.33558.Cy0@aC4W73oi
CyrenW32/LoadMoney.AI.gen!Eldorado
SymantecTrojan.Gen.MBT
TotalDefenseWin32/Ogiman.SIaTdS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Loadmoney-12553
GDataGen:Heur.Krypt.12
Kasperskynot-a-virus:Downloader.Win32.Plocust.nhad
AlibabaDownloader:Win32/Plocust.acfa9dea
NANO-AntivirusTrojan.Win32.Plocust.dibijk
ViRobotAdware.Loadmoney.474112.IO
AvastWin32:LoadMoney-APN [Adw]
RisingAdware.LoadMoney!1.AE40 (CLASSIC)
Ad-AwareGen:Heur.Krypt.12
SophosTroj/LdMon-J
ComodoApplication.Win32.LoadMoney.XUN@5hsu1v
F-SecurePotentialRisk.PUA/LoadMoney.Gen7
BaiduWin32.Adware.Kryptik.c
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroPossible_Ogimant
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.Krypt.12 (B)
Ikarusnot-a-virus:Downloader.Plocust
F-ProtW32/LoadMoney.AI.gen!Eldorado
JiangminPacked.Krap.evhb
WebrootW32.Adware.Gen
AviraPUA/LoadMoney.Gen7
Antiy-AVLRiskWare[Downloader]/Win32.Plocust.nhad
Endgamemalicious (high confidence)
ArcabitTrojan.Krypt.12
ZoneAlarmnot-a-virus:Downloader.Win32.Plocust.nhad
MicrosoftSoftwareBundler:Win32/Ogimant
AhnLab-V3PUP/Win32.LoadMoney.R124472
Acronissuspicious
ALYacGen:Heur.Krypt.12
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Limpopo
MalwarebytesAdware.LoadMoney
ESET-NOD32Win32/Adware.LoadMoney.RM
TrendMicro-HouseCallPossible_Ogimant
TencentMalware.Win32.Gencirc.10b58962
YandexPUA.LoadMoney!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.CPAR!tr
AVGWin32:LoadMoney-APN [Adw]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Virus.06b

How to remove Heur.Krypt.12?

Heur.Krypt.12 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment