Malware

Win32/Kryptik.HAZU removal guide

Malware Removal

The Win32/Kryptik.HAZU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HAZU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system

Related domains:

whitecontroller.com

How to determine Win32/Kryptik.HAZU?


File Info:

crc32: 956CD142
md5: a7fac5e673d9eb7033c5a0a6bea216c7
name: iec60617downloadfree-rtmd-ahlep14obgaatbecaerffwasabmjauea.exe
sha1: 9ce613438ec2d68606e3f56c9efbb31881687d56
sha256: 30a79ee748d000b2fd279c9974f106547064c7f85360d40c7f244216ad122753
sha512: 1ae1c5333d5ccab34329ffd32e46b3d9e08ab8f5e6d268e4d45a8c4fc357ec3a114084539506ae1dc9229a99265d20f225e75e19d4ddaac95c3148934eefe97b
ssdeep: 98304:7EvygVGqqYFjDxkleczM6HeyLPwEMtAjeb:7E3G9qjDxCePLk4EMtAw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0215 0x007b

Win32/Kryptik.HAZU also known as:

BkavHW32.Packed.
DrWebTrojan.Siggen9.10468
MicroWorld-eScanGen:Variant.Mikey.109585
FireEyeGeneric.mg.a7fac5e673d9eb70
Qihoo-360Generic/HEUR/QVM20.1.29A9.Malware.Gen
McAfeeArtemis!A7FAC5E673D9
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
BitDefenderGen:Variant.Mikey.109585
K7GWTrojan ( 0056053d1 )
Cybereasonmalicious.38ec2d
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
GDataWin32.Trojan-Downloader.Glupteba.R0BOXK
KasperskyTrojan-Downloader.Win32.Bandit.lst
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.GoCloudnet.iypt
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ransom.wc
Trapminemalicious.moderate.ml.score
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.iypt
MicrosoftTrojan:Win32/Glupteba.D!bit
ZoneAlarmTrojan-Downloader.Win32.Bandit.lst
AhnLab-V3Trojan/Win32.MalPe.R325519
Acronissuspicious
ESET-NOD32a variant of Win32/Kryptik.HAZU
RisingTrojan.Glupteba!8.AA0 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HAYZ!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HAZU?

Win32/Kryptik.HAZU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment