Malware

About “Win32/Kryptik.HBUT” infection

Malware Removal

The Win32/Kryptik.HBUT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBUT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HBUT?


File Info:

crc32: D209073C
md5: b7734ccff4071ea84766b7beb8d6c452
name: vps.exe
sha1: ebe7a18655f1ac04a9dc43ce224f0879316dcb06
sha256: 27d15cd64e2dbe4366103230b210d06bced49cf111f31d59c970d262d1c95e2e
sha512: a24723c5cb4b4fade941163e0c1ef1a85ad6a4a32742a524ed430165866f4d3d75a2b14836b9c6a03477e56a2dd0fd6d5c7adeaa18b715847d1c62b9fd5a0179
ssdeep: 12288:LJfaxPoPTaXbMlkP36MIuufZEpbV3L9x9Zz2FLxvRxtSR:LExwQMA36z1C9V3L9xLz2FLxpx8
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HBUT also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKDZ.65379
FireEyeGeneric.mg.b7734ccff4071ea8
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKDZ.65379
K7GWHacktool ( 700007861 )
BitDefenderThetaGen:NN.ZexaF.34098.OKW@a06zj6D
SymantecTrojan.Gen.2
Paloaltogeneric.ml
GDataTrojan.GenericKDZ.65379
KasperskyUDS:DangerousObject.Multi.Generic
AvastWin32:TrojanX-gen [Trj]
Endgamemalicious (high confidence)
SophosMal/Generic-S
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.65379 (B)
APEXMalicious
MAXmalware (ai score=87)
ArcabitTrojan.Generic.DFF63
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/RanumBot.GA!MTB
SentinelOneDFI – Suspicious PE
AhnLab-V3Trojan/Win32.MalPe.R328174
Acronissuspicious
VBA32BScope.Trojan.AET.281105
Ad-AwareTrojan.GenericKDZ.65379
MalwarebytesSpyware.Agent
ESET-NOD32a variant of Win32/Kryptik.HBUT
RisingTrojan.RanumBot!8.112AC (TFE:dGZlOgUo0fIvhXM/HA)
eGambitUnsafe.AI_Score_75%
FortinetW32/GenKryptik.HBUR!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Win32/Kryptik.HBUT?

Win32/Kryptik.HBUT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment