Malware

Win32/Kryptik.HATV removal instruction

Malware Removal

The Win32/Kryptik.HATV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HATV virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

whitecontroller.com

How to determine Win32/Kryptik.HATV?


File Info:

crc32: 23295C1E
md5: 720a612077a422109df3c8945e088308
name: spellforce-gold-edition-trainer-rtmd-ai6alv5ocgaa6rocafbmfwamandirn8a.exe
sha1: 14ae2f30c62b716dc97c58d3dfc7954143f950d7
sha256: cfcee9378aacb84c082b3e8e6f249baa66f9758ecd0709e8d1a5b618396a1d5e
sha512: 83e6e64774e7d878d6badabc7222861c45fe0651368475211d4a392091874a5d3d40bcc0532b2e7c99e28e48f64a3dd1d5393603574e3d318c9a55099219088b
ssdeep: 98304:5vorfA4vHgbj1Wjkkhp9ZqX77SjpOI7x6fojW93:WLA71W5/kS6AjW9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0215 0x04e5

Win32/Kryptik.HATV also known as:

MicroWorld-eScanTrojan.GenericKDZ.62646
FireEyeGeneric.mg.720a612077a42210
SangforMalware
BitDefenderTrojan.GenericKDZ.62646
Cybereasonmalicious.0c62b7
ESET-NOD32a variant of Win32/Kryptik.HATV
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKDZ.62646
KasperskyTrojan.Win32.Chapak.eigd
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Kryptik!8.8 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKDZ.62646 (B)
F-SecureTrojan.TR/AD.GoCloudnet.irwl
DrWebTrojan.Siggen9.8302
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Trojan.wc
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
WebrootW32.Malware.Gen
AviraTR/AD.GoCloudnet.irwl
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Bandit
AhnLab-V3Packed/Win32.SuspiciousPacker.R325374
ZoneAlarmTrojan.Win32.Chapak.eigd
Acronissuspicious
McAfeeGenericRXAA-AA!720A612077A4
MAXmalware (ai score=81)
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.Injector
IkarusTrojan.Win32.Crypt
Ad-AwareTrojan.GenericKDZ.62646
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.998

How to remove Win32/Kryptik.HATV?

Win32/Kryptik.HATV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment