Malware

Win32/Kryptik.HAWX information

Malware Removal

The Win32/Kryptik.HAWX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HAWX virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Gaelic (Scottish)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system

Related domains:

whitecontroller.com

How to determine Win32/Kryptik.HAWX?


File Info:

crc32: 342A1A2A
md5: aacba60cde672b09a1d58e1111d479be
name: the-beat-of-the-pops-volume-3-rtmd-aag5ol4obgaatbecaerffwasajy3qzea.exe
sha1: 9302d178b43a4db99bce3a5508b1e7346404bd44
sha256: 7366766e1910ff2065f63c7ab962bd698bdb23a36230208626d6d70e5e508bb8
sha512: 8ba0b9fbae7c23c21753386b5c45b72d09568bd7c3d87581d8feac3dcb868d612c3dc9214fb54ed38ce8d167341ce8cc0ed58dd24a32b974259a86707d49be0c
ssdeep: 98304:v81SRwIpI/e1lAnQl8qRGtCm8jZPZQSdQXK:01Olce11lbY70GX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019, tail
InternalServiceName: sfsgvsdg.exe
FileVersion: 5.3.4

Win32/Kryptik.HAWX also known as:

BkavW32.AIDetectVM.malware
FireEyeGeneric.mg.aacba60cde672b09
McAfeeArtemis!AACBA60CDE67
CylanceUnsafe
SangforMalware
BitDefenderThetaGen:NN.ZexaF.34084.YF0@aiS4ARpG
SymantecML.Attribute.HighConfidence
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Kryptik!1.C0F7 (CLASSIC)
Endgamemalicious (high confidence)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.wc
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HAWX
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
WebrootW32.Adware.Gen
AVGWin32:MdeClass
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM10.2.0F63.Malware.Gen

How to remove Win32/Kryptik.HAWX?

Win32/Kryptik.HAWX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment