Malware

Win32/Kryptik.HBHH removal tips

Malware Removal

The Win32/Kryptik.HBHH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBHH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Detects Avast Antivirus through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tldrbox.top

How to determine Win32/Kryptik.HBHH?


File Info:

crc32: CA60D5A7
md5: 1315b141a5c6bd2f318c1067c1889ae1
name: o.exe
sha1: 7c0393c16dac1497269940c61b8330f8fb744ada
sha256: e17746721dc1d611064d265b420efaa2790be03d8380c16e9519cab6cb6fa609
sha512: 28d1e65af40a3556c2e38b83ba117bd5b468df9c68e1c0a246f41f444841bc7daf93b450ce09ae568de8af5453a5d184bdddebe76376a177ed12143567f2e05a
ssdeep: 1536:FsWjVJuebsp3Otd9KzBgQQA5qrLDM67q1KvQM8iXmLZbz:FxSp3OtLYL5qrLICq1KIKmL1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersionNew: 2.3.4
InternalServiceName: speedy.exe
Copyright: Copyright (C) 2020, softtail

Win32/Kryptik.HBHH also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33319697
FireEyeGeneric.mg.1315b141a5c6bd2f
Qihoo-360Generic/HEUR/QVM10.2.5E21.Malware.Gen
McAfeeArtemis!1315B141A5C6
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33319697
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34090.hyW@a8Re@aoG
CyrenW32/Trojan.CAGI-7807
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HBHH
Paloaltogeneric.ml
KasperskyTrojan.Win32.Fsysna.gcrp
AlibabaTrojan:Win32/Starter.ali2000005
RisingBackdoor.Tofsee!8.1E9 (CLOUD)
Ad-AwareTrojan.GenericKD.33319697
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Phorpiex.abax
DrWebTrojan.MulDrop4.25343
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.33319697 (B)
APEXMalicious
WebrootW32.Trojan.Gen
FortinetW32/Kryptik.HBHH!tr
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FC6B11
ZoneAlarmTrojan.Win32.Fsysna.gcrp
MicrosoftBackdoor:Win32/Tofsee.BS!MTB
Acronissuspicious
MAXmalware (ai score=89)
VBA32BScope.Trojan.AET.281105
PandaTrj/GdSda.A
TencentWin32.Trojan.Fsysna.Dumf
SentinelOneDFI – Suspicious PE
GDataWin32.Trojan.Agent.YAXF3C
AVGFileRepMalware
Cybereasonmalicious.1a5c6b
AvastFileRepMalware

How to remove Win32/Kryptik.HBHH?

Win32/Kryptik.HBHH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment