Malware

Win32/Kryptik.DHFK removal instruction

Malware Removal

The Win32/Kryptik.DHFK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DHFK virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Romanian
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Mimics icon used for popular non-executable file format
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.DHFK?


File Info:

name: E90202F5B3FB25D67308.mlw
path: /opt/CAPEv2/storage/binaries/3fbfc928f7052883705d5e57897e8bb82d8908c1c48ea4b76fd31a1246b2f544
crc32: BDBFAC93
md5: e90202f5b3fb25d67308ff773683b2ce
sha1: 88ee61d131e57268264181eebf0f8679f5e66929
sha256: 3fbfc928f7052883705d5e57897e8bb82d8908c1c48ea4b76fd31a1246b2f544
sha512: 710f41a4b8f5b06f81c90fb51a69a3d02c22f1786a2fa741ed75688a6f5a37e5d7affee4dee1947510682175f2b83163fe474e84ea3266bd794f5ae5ffb832a1
ssdeep: 768:0KFLvH7h+pgD/E/qPE1wc4yGSkW1rR2cju+ceq1EIaLLj5oZiSQB7ose7YNExJ+o:JL/7h+pgD/jPQ54yGSkCrR2cju+ceq1U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152F2C411DAD6C9C0CC086F7845B798341256BD39FDB9F8A97C8C39292B736C2366934B
sha3_384: 3f422dfffec3ee84e55b9306060c6678d6a39ebfda9b5c6587ea941d4db8fed1f163f85ff053aded9aa411a45b8c78dd
ep_bytes: 558bec6aff68d84b400068d228400064
timestamp: 2014-01-08 00:48:18

Version Info:

0: [No Data]

Win32/Kryptik.DHFK also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.mv8z
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.e90202f5b3fb25d6
CAT-QuickHealTrojan.Kadena.B4
ALYacTrojan.Upatre.Gen.3
MalwarebytesTrojan.Upatre
ZillyaDownloader.CTBLockerGen.Win32.5
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004c2ec91 )
AlibabaMalware:Win32/km_24dec.None
K7GWTrojan ( 004c2ec91 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Generic.EPP
CyrenW32/Dalexis.H.gen!Eldorado
SymantecDownloader.Upatre!gm
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.DHFK
APEXMalicious
KasperskyTrojan-Downloader.Win32.Upatre.jgz
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.drgfjr
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Dyre-K [Trj]
TencentMalware.Win32.Gencirc.10b34a07
TACHYONTrojan-Downloader/W32.Upatre.35840.W
EmsisoftTrojan.Upatre.Gen.3 (B)
F-SecureTrojan.TR/Yarwi.cjamnb
DrWebTrojan.DownLoader13.9722
VIPRETrojan.Upatre.Gen.3
TrendMicroTROJ_UPATRE.SM05
McAfee-GW-EditionUpatre-FABR!E90202F5B3FB
Trapminemalicious.high.ml.score
SophosTroj/Bredo-APR
IkarusTrojan-Spy.Agent
GDataTrojan.Upatre.Gen.3
JiangminTrojanDownloader.Upatre.bfh
GoogleDetected
AviraTR/Yarwi.cjamnb
Antiy-AVLTrojan[Downloader]/Win32.Upatre.jgz
XcitiumTrojWare.Win32.TrojanDownloader.Upatre.MAUA@5rueuc
ArcabitTrojan.Upatre.Gen.3
ZoneAlarmTrojan-Downloader.Win32.Upatre.jgz
MicrosoftTrojanDownloader:Win32/Upatre.BC
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R146889
McAfeeUpatre-FACA!E90202F5B3FB
MAXmalware (ai score=85)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM05
RisingTrojan.Win32.Kryptik.af (CLASSIC)
YandexTrojan.GenAsa!7n/7L+TBO7Y
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.DIZF!tr
BitDefenderThetaGen:NN.ZexaF.36318.cqW@aiVszzpG
AVGWin32:Dyre-K [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.DHFK?

Win32/Kryptik.DHFK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment