Malware

Should I remove “Win32/Kryptik.HAHB”?

Malware Removal

The Win32/Kryptik.HAHB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HAHB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

google.pt

How to determine Win32/Kryptik.HAHB?


File Info:

crc32: C6C5E847
md5: 78062ec905573e970db7df061ff066f4
name: server.exe
sha1: fa680eba41944f5362e850436dc95edf8670d8da
sha256: fb4d3ec1a366fa94a69a0ecdf77c529526ff326c40f70d9a6a16f8726099c59e
sha512: 90661d5e57a1e0bb96bf7dd2106645df71963806135d908fda48974611fe4bca8e7411316e678186270f1d22c952298066917d948559731716bb1e7360a34633
ssdeep: 12288:Z5jDLHuBlJsVa0qxDNwEe+Scn+ZQneuvrE+el90xt:ZtDLHuBlJsVtwD+Ee+Sc+gjrE+eDk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HAHB also known as:

MicroWorld-eScanGen:Variant.Ulise.98675
McAfeePacked-FYY!78062EC90557
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055eec61 )
BitDefenderGen:Variant.Ulise.98675
K7GWTrojan ( 0055eec61 )
Cybereasonmalicious.a41944
ArcabitTrojan.Ulise.D18173
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAHB
APEXMalicious
KasperskyTrojan-Spy.Win32.AveMaria.ctq
NANO-AntivirusTrojan.Win32.Maria.gyvrlf
RisingSpyware.AveMaria!8.108C2 (C64:YzY0Ot0Drdg24mxM)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ulise.98675 (B)
F-SecureTrojan.TR/Crypt.Agent.ynjka
DrWebTrojan.PWS.Maria.3
ZillyaTrojan.AveMaria.Win32.435
McAfee-GW-EditionPacked-FYY!78062EC90557
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.78062ec905573e97
IkarusTrojan.Win32.Agent
JiangminTrojanSpy.AveMaria.ho
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.ynjka
MAXmalware (ai score=81)
Antiy-AVLTrojan[Spy]/Win32.AveMaria
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmTrojan-Spy.Win32.AveMaria.ctq
AhnLab-V3Malware/Win32.Generic.C3980620
Acronissuspicious
VBA32TrojanSpy.AveMaria
ALYacGen:Variant.Ulise.98675
Ad-AwareGen:Variant.Ulise.98675
PandaTrj/GdSda.A
YandexTrojanSpy.AveMaria!
SentinelOneDFI – Suspicious PE
GDataGen:Variant.Ulise.98675
BitDefenderThetaGen:NN.ZexaF.34100.@uW@auYzA3hi
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.74813064.susgen

How to remove Win32/Kryptik.HAHB?

Win32/Kryptik.HAHB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment