Malware

Win32/Kryptik.HAIZ information

Malware Removal

The Win32/Kryptik.HAIZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HAIZ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HAIZ?


File Info:

crc32: AB74C7B4
md5: 45ed48498d907d84573c5620d2da508d
name: zFMwJft8bHg0.exe
sha1: 7ff3d309ad4c23642d8e17be2ba6cd07516b752c
sha256: 44de1fda3315e9140ee467547a856e9e3c7f5f683b22b852590f69e2327be269
sha512: 81d3d8028dd0c2c0a59d7800d9e8b65bf140bd998f0c1f9cce7fab401c1b628db2fecde0370a604e9a55359126d9ede442c13eb1d04f161981a3e96c9d345a1f
ssdeep: 6144:0T2ZfcAZDQvEL9QdUW1UWKUWV197qo1Dplm:C2ZC8SdUAUHUq19Oole
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2002
InternalName: PromptEdit_Demo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: PromptEdit_Demo Application
ProductVersion: 1, 0, 0, 1
FileDescription: PromptEdit_Demo MFC Application
OriginalFilename: PromptEdit_Demo.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HAIZ also known as:

FireEyeTrojan.GenericKD.32958434
McAfeeEmotet-FPC!45ED48498D90
ALYacTrojan.GenericKD.32958434
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0055ef991 )
BitDefenderTrojan.GenericKD.32958434
K7GWTrojan ( 0055ef991 )
BitDefenderThetaGen:NN.ZexaF.34082.uq1@aa!iGaki
F-ProtW32/Emotet.ANF
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HAIZ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Emotet-7545662-0
GDataTrojan.GenericKD.32958434
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/starter.ali1000037
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/AD.Emotet.jzvhc
DrWebTrojan.DownLoader32.49007
TrendMicroTrojanSpy.Win32.EMOTET.THAAGBO
McAfee-GW-EditionEmotet-FPC!45ED48498D90
Trapminemalicious.high.ml.score
SophosMal/Encpk-AOZ
IkarusTrojan.Win32.Krypt
CyrenW32/Emotet.SCYR-7043
JiangminTrojan.Banker.Emotet.ncn
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.jzvhc
MAXmalware (ai score=87)
ArcabitTrojan.Generic.D1F6E7E2
AhnLab-V3Malware/Win32.RL_Generic.R313373
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
VBA32BScope.Trojan.Downloader
Ad-AwareTrojan.GenericKD.32958434
MalwarebytesTrojan.Emotet
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMD6.hp
TencentMalware.Win32.Gencirc.10b8b478
FortinetW32/GenKryptik.ECEO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Generic/Trojan.a4b

How to remove Win32/Kryptik.HAIZ?

Win32/Kryptik.HAIZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment