Malware

How to remove “Win32/Kryptik.HBRH”?

Malware Removal

The Win32/Kryptik.HBRH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBRH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

vaxton.xyz

How to determine Win32/Kryptik.HBRH?


File Info:

crc32: 9D7FCDD8
md5: cd11bfa08198088b68baa69aee360c24
name: m.exe
sha1: b30dff426ee38b703cdf6cf06bf0b1fa43031754
sha256: c6f361f9bbbefc96f962d2860914e7b5bbc934b9aee7dbdde3221fe3e67890e2
sha512: 50281fbd2727ac0777affb87099810fdcd9b9833a90af7e289d633e9e1534353daa105aa521eaee9aa374f6b42a9428b3e1d968e061ab94d2526445df0ebfffa
ssdeep: 49152:18D6OjiCZUkes2KXEHytTJLeIQqXCE2UC:QL/pessHytTJLNQqz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9Stellar Information Technology Pvt. Ltd. 1995-Present
FileVersion: 3.3.8.399
CompanyName: Stellar Information Technology Pvt. Ltd.
FileDescription: Catch Utings Possession
LegalTrademarks: Copyright xa9Stellar Information Technology Pvt. Ltd. 1995-Present
Comments: Catch Utings Possession
ProductName: Subdivisin
ProductVersion: 3.3.8.399
PrivateBuild: 3.3.8.399
Translation: 0x0409 0x04b0

Win32/Kryptik.HBRH also known as:

MicroWorld-eScanTrojan.GenericKD.33505912
Qihoo-360Win32/Trojan.f7a
McAfeeArtemis!CD11BFA08198
AegisLabTrojan.Win32.BitCoinMiner.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33505912
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderThetaGen:NN.ZexaF.34098.pw0@auqP!Hpi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R049H0CC520
Paloaltogeneric.ml
GDataTrojan.GenericKD.33505912
KasperskyTrojan.Win32.BitCoinMiner.esv
AlibabaTrojan:Win32/BitCoinMiner.4f691e7f
AvastWin32:Malware-gen
TencentWin32.Trojan.Bitcoinminer.Syrh
Ad-AwareTrojan.GenericKD.33505912
SophosMal/Generic-S
F-SecureTrojan.TR/AD.CoinMiner.hsp
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
SentinelOneDFI – Suspicious PE
FireEyeGeneric.mg.cd11bfa08198088b
EmsisoftTrojan.GenericKD.33505912 (B)
APEXMalicious
CyrenW32/Trojan.IUFH-8917
WebrootW32.Trojan.Gen
AviraTR/AD.CoinMiner.hsp
Antiy-AVLTrojan/Win32.BitCoinMiner
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FF4278
ZoneAlarmTrojan.Win32.BitCoinMiner.esv
MicrosoftTrojan:Win32/CoinMiner.BW!bit
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacTrojan.GenericKD.33505912
MAXmalware (ai score=87)
ESET-NOD32a variant of Win32/Kryptik.HBRH
RisingTrojan.Generic@ML.85 (RDML:OT4G7awALL8jae+8F5o+2g)
IkarusTrojan-Ransom.Crysis
eGambitUnsafe.AI_Score_97%
FortinetW32/BitCoinMiner.ESV!tr
AVGWin32:Malware-gen
Cybereasonmalicious.26ee38
PandaTrj/CI.A

How to remove Win32/Kryptik.HBRH?

Win32/Kryptik.HBRH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment