Malware

How to remove “Win32/Kryptik.AHNH”?

Malware Removal

The Win32/Kryptik.AHNH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AHNH virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Likely installs a bootkit via raw harddisk modifications
  • Deletes its original binary from disk
  • Attempts to restart the guest VM
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.AHNH?


File Info:

crc32: EC171E1E
md5: c4558335d230aa596622851ab9a303fd
name: C4558335D230AA596622851AB9A303FD.mlw
sha1: b9d41942e1628dda3f61281cba3c2e6e26787e7c
sha256: 53d04861defbbf4dd0873f81b12b61637181e73541d008ff8bfae7b6deb8ddfe
sha512: a740f2887ed67b6f2d24d11073c912d871f94265cf1f7fd1aa9abeeb9e0a1112b3803a5ca9ede47ce8acbfb4fbb658d6b31edfd36044f1bcf3e3837c9acf1bf8
ssdeep: 384:wkVhgI4mhtYq1tldPoTByJmvz3Mtwc2aPn/HYM4TIZMJlsLm:H6I4m8qb2YILenHYOaJaLm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.AHNH also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MBRlock.30
CynetMalicious (score: 99)
ALYacGen:Variant.Kazy.66788
CylanceUnsafe
ZillyaTrojan.Mbro.Win32.1324
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Genasom.77ec0c73
Cybereasonmalicious.5d230a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AHNH
APEXMalicious
AvastWin32:Cryptor
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Kazy.66788
NANO-AntivirusTrojan.Win32.Mbro.vgpsk
ViRobotTrojan.Win32.A.Mbro.22528.F
MicroWorld-eScanGen:Variant.Kazy.66788
TencentWin32.Trojan.Mbro.Swuf
Ad-AwareGen:Variant.Kazy.66788
SophosMal/Generic-R + Mal/EncPk-AEG
ComodoMalware@#10oq8v1rlrevd
BitDefenderThetaGen:NN.ZexaF.34678.bqW@amaCf4g
VIPRETrojan.Win32.Autorun.as (v)
McAfee-GW-EditionGenericRXNA-IW!C4558335D230
FireEyeGeneric.mg.c4558335d230aa59
EmsisoftGen:Variant.Kazy.66788 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/MBro.ui
WebrootW32.Malware.Gen
AviraTR/Ransom.Mbro.4
eGambitGeneric.Malware
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Genasom.DV
GDataGen:Variant.Kazy.66788
AhnLab-V3Trojan/Win32.Gen
Acronissuspicious
McAfeeGenericRXNA-IW!C4558335D230
MAXmalware (ai score=99)
VBA32BScope.Trojan.MBRlock
PandaTrj/Pacrypt.F
RisingRansom.Genasom!8.293 (CLOUD)
YandexTrojan.GenAsa!giHo52bCBIs
IkarusTrojan.Win32.Ransom
FortinetW32/Zbot.CGZF!tr
AVGWin32:Cryptor
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Genasom.HxMBEpsA

How to remove Win32/Kryptik.AHNH?

Win32/Kryptik.AHNH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment