Malware

Win32/Kryptik.HBPC malicious file

Malware Removal

The Win32/Kryptik.HBPC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBPC virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine Win32/Kryptik.HBPC?


File Info:

crc32: 661F277C
md5: aaee5f1fac2dcc0957cd853e3acc5adc
name: admnn.exe
sha1: 96ef512e1219dc6660d1133af768e05658b57edb
sha256: 96fa40ed0c1cbdd62c6772a03f9c136164e3f1fa02acfcccce9ee1cb832bf5b1
sha512: eead1c52d8053a9431961f608fc54b4e82569e5d90e3cc7753623530e7d351fc9fa00fc94210ae9e06201604b1ee79f9b361e123899662b9e342d1ab06605956
ssdeep: 1536:mR/cswGho5Dg5T5NLIgwZFXMCNVLRJw6j9OmcK9K4G:mFPT5T5NkgyM2VLRJw6j9AK9K4G
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1999
InternalName: Self Extractor Builder
FileVersion: 1.00
CompanyName:
ProductName: Self Extractor Builder
ProductVersion: 1.00
FileDescription: Self Extractor Builder
OriginalFilename: Self Extractor.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HBPC also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Graftor.714926
FireEyeGen:Variant.Graftor.714926
Qihoo-360Win32/Backdoor.f5f
ALYacGen:Variant.Graftor.714926
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005619351 )
BitDefenderGen:Variant.Graftor.714926
K7GWTrojan ( 005619351 )
TrendMicroTROJ_GEN.R002C0DCT20
CyrenW32/Trojan.IM1.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0DCT20
AvastWin32:BackdoorX-gen [Trj]
GDataGen:Variant.Graftor.714926
KasperskyHEUR:Backdoor.Win32.Lotok.vho
AlibabaBackdoor:Win32/Zegost.73a1f9d8
NANO-AntivirusTrojan.Win32.Lotok.helpux
ViRobotTrojan.Win32.Z.Lotok.94208
AegisLabTrojan.Win32.Lotok.m!c
TencentMalware.Win32.Gencirc.10b906da
Ad-AwareGen:Variant.Graftor.714926
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.PDSB@4q3i1w
F-SecureTrojan.TR/AD.Farfli.fbqvw
DrWebTrojan.DownLoader33.12796
ZillyaTrojan.Lotok.Win32.22
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.nm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.714926 (B)
APEXMalicious
F-ProtW32/Trojan.IM1.gen!Eldorado
JiangminBackdoor.Lotok.ei
AviraTR/AD.Farfli.fbqvw
MAXmalware (ai score=80)
Antiy-AVLTrojan[Backdoor]/Win32.Lotok
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.DAE8AE
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.BW
AhnLab-V3Backdoor/Win32.Agent.C4016752
Acronissuspicious
McAfeeArtemis!AAEE5F1FAC2D
VBA32BScope.Backdoor.Zegost
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBPC
RisingBackdoor.Lotok!8.111D5 (CLOUD)
YandexTrojan.Kryptik!C9QZqAKrsdI
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.EGBG!tr
AVGWin32:BackdoorX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Kryptik.HBPC?

Win32/Kryptik.HBPC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment