Malware

What is “Win32/Kryptik.HBAI”?

Malware Removal

The Win32/Kryptik.HBAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBAI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HBAI?


File Info:

crc32: 25089F06
md5: d097616a8a4a281fdcbc21e7c9d879c7
name: D097616A8A4A281FDCBC21E7C9D879C7.mlw
sha1: 9ae2b640e5dc3feaefa115eabd4c4a29f3ab359d
sha256: 620202888a810ab3dbbc3a3b4e6aaacb621a03a280b0cb2e647356064ab15393
sha512: c095beb9f7a6819a911600b9a98a6652df0701bd6c11abdf2316aeba3f7bf80189c8809826fd0ce3decd1faf5bada9d989ef6a1e4159d368fc574e703e1fdacc
ssdeep: 24576:a6cDeOeHMKCMW5lnpFvDJa4nq5qfzNLt:a6cDeOeHMKxW5lpFbjnffzNL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018 Ariolic Software, Ltd
InternalName: asmartCore
FileVersion: 2.10.2.167
CompanyName: Ariolic Software, Ltd. (www.ariolic.com)
Comments: ab28886af3b6f732ef902aaf66703c121f6899eb
ProductName: ActiveSMART
ProductVersion: 2.10.2.167
FileDescription: ActiveSMART (R) - Hard drive health and files audit utility
OriginalFilename: ASmartCore.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.HBAI also known as:

K7AntiVirusTrojan ( 0058214e1 )
Elasticmalicious (high confidence)
CylanceUnsafe
K7GWTrojan ( 0058214e1 )
Cybereasonmalicious.0e5dc3
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBAI
ZonerProbably Heur.ExeHeaderH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Staser.gen
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
FireEyeGeneric.mg.d097616a8a4a281f
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1IAKRUN
McAfeeGenericRXOV-UA!D097616A8A4A
MalwarebytesAdware.DownloadAssistant
RisingMalware.Heuristic!ET#85% (RDMK:cmRtazomy/jFcavDghIohd2LX8qZ)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HATU!tr

How to remove Win32/Kryptik.HBAI?

Win32/Kryptik.HBAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment