Malware

Win32/Kryptik.HBIY malicious file

Malware Removal

The Win32/Kryptik.HBIY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBIY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • The binary likely contains encrypted or compressed data.
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tldrbox.top

How to determine Win32/Kryptik.HBIY?


File Info:

crc32: 72ED3B0D
md5: c224753af36640f7455dc47848ebeecd
name: o.exe
sha1: 17b915dc3d863998d8c64eca05944c779f6204fb
sha256: a46ea9f3a128fb0c3cd91a3c00b719e8c0bc59430c20813f5b7541837da449f6
sha512: 7c99fcbf2e4814aecd71be805880dceea2de5ff7892e06a73a8c084196d066ef1246572f80995e736f79e65c010ee65fc7cdb9d5d7637090520f0abfbb9136f8
ssdeep: 3072:iqBNIBNaMMXPHo7ntgAist930NcV5kqr/54vyOXzGA27C9mv3epNGkZp:i+i5YPI7i7a9acV5kqr/5sTd2W9mv7c
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0115 0x007b

Win32/Kryptik.HBIY also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33362820
FireEyeGeneric.mg.c224753af36640f7
McAfeeRDN/Generic.grp
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005611f71 )
BitDefenderTrojan.GenericKD.33362820
K7GWTrojan ( 005611f71 )
Cybereasonmalicious.c3d863
Invinceaheuristic
F-ProtW32/Emotet.AHU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBIY
TrendMicro-HouseCallTROJ_GEN.R011C0PBO20
Paloaltogeneric.ml
GDataTrojan.GenericKD.33362820
KasperskyTrojan.Win32.Fsysna.gcwl
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.Fsysna.hbqgns
ViRobotTrojan.Win32.S.Downloader.254976.A
APEXMalicious
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#39yynfso47o9
F-SecureTrojan.TR/AD.Phorpiex.qoscp
DrWebWin32.HLLW.Phorpiex.1367
TrendMicroTROJ_GEN.R011C0PBO20
McAfee-GW-EditionRDN/Generic.grp
Trapminesuspicious.low.ml.score
EmsisoftTrojan.Crypt (A)
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.PUOH-8117
JiangminTrojan.PSW.Racealer.abd
AviraTR/AD.Phorpiex.qoscp
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1FD1384
AegisLabRiskware.Win32.Generic.1!c
AhnLab-V3Trojan/Win32.MalPe.R327030
ZoneAlarmTrojan.Win32.Fsysna.gcwl
Acronissuspicious
TACHYONTrojan/W32.Fsysna.254976.B
Ad-AwareTrojan.GenericKD.33362820
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TencentWin32.Trojan.Fsysna.Suwy
IkarusTrojan.Win32.Krypt
FortinetW32/Fsysna.GCWL!tr
AVGWin32:CrypterX-gen [Trj]
AvastWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM20.1.6AE9.Malware.Gen

How to remove Win32/Kryptik.HBIY?

Win32/Kryptik.HBIY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment