Malware

Should I remove “Win32/Kryptik.HBEV”?

Malware Removal

The Win32/Kryptik.HBEV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBEV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Win32/Kryptik.HBEV?


File Info:

crc32: 74377985
md5: 03b8cffa573f4dac8f65b6a40a0e1787
name: man3.exe
sha1: 0dacbc2c43519d28ba9ca90707885ff5e7baaf19
sha256: 0d2e728a82774eee23b1139439d85d087d36983e60630c7b1ba2014bc7a68673
sha512: f5c84f917a9a4b331030a215d27fa6792454df08432a8a49eb3f388a2480eaab83305f8a03f5a5f6cfacd0d406b9cf1034f8e5f1c42a670cefdc4fdd6fb74a0c
ssdeep: 12288:5sAW3pWpn15riRwXBZTyEJso4VjprIOuTHyknqZ:v7GRwRcXVtkBT3+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2008
InternalName: WinHttpGatewayTest
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: WinHttpGatewayTest Application
ProductVersion: 1, 0, 0, 1
FileDescription: WinHttpGatewayTest MFC Application
OriginalFilename: WinHttpGatewayTest.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HBEV also known as:

DrWebTrojan.Trick.46525
MicroWorld-eScanTrojan.GenericKD.33293371
FireEyeTrojan.GenericKD.33293371
Qihoo-360Generic/HEUR/QVM07.1.5129.Malware.Gen
McAfeeRDN/Generic.grp
SangforMalware
BitDefenderTrojan.GenericKD.33293371
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaE.34090.Xy0@aubHIMmk
CyrenW32/Emotet.AHR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBEV
APEXMalicious
KasperskyTrojan.Win32.Inject.amscz
NANO-AntivirusTrojan.Win32.Trick.hbbtkg
TencentWin32.Trojan.Inject.Fie
Ad-AwareTrojan.GenericKD.33293371
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/AD.TrickBot.gufrf
TrendMicroTROJ_FRS.VSNTBH20
McAfee-GW-EditionRDN/Generic.grp
SophosTroj/Agent-BDPP
IkarusTrojan.Win32.Crypt
F-ProtW32/Emotet.AHR.gen!Eldorado
WebrootW32.Trojan.Emotet
AviraTR/AD.TrickBot.gufrf
Antiy-AVLTrojan/Win32.Detplock
MicrosoftTrojan:Win32/TrickBot!MTB
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FC043B
ZoneAlarmTrojan.Win32.Inject.amscz
GDataTrojan.GenericKD.33293371
ALYacTrojan.Trickster.Gen
MAXmalware (ai score=81)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_FRS.VSNTBH20
RisingTrojan.Trickbot!8.E313 (CLOUD)
FortinetW32/Kryptik.EEDP!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]

How to remove Win32/Kryptik.HBEV?

Win32/Kryptik.HBEV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment