Malware

How to remove “Win32/Kryptik.HBUW”?

Malware Removal

The Win32/Kryptik.HBUW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBUW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Unconventionial language used in binary resources: Japanese
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HBUW?


File Info:

crc32: DFAAB168
md5: 510bdd4b3eef55b0255f7069894d2b60
name: vps.exe
sha1: 1507338779a2a790744ff835372d8bf63dfd7ea7
sha256: 6928f88aa669b85dae89cb7923a5fa1af097062661aeaf6b8b1b73c34dc826d9
sha512: c7f07d23b34dbf025a9b38f03bcc30d40c6513f0d7fcd36b7790e36e657b2577e12e3f26022b86711fcf66a0f5aadeed4970e425c1b3a47f9ceb1aee5b9c5eba
ssdeep: 12288:ghfKpzAYzxm6CfaCIwkW2Z81c5KQ0K+ImzN7tb5n1aqdtTZa2c:ifKpzy1BQ81cLkIQNJbtUqdTO
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HBUW also known as:

BkavW32.AIDetectVM.malware
FireEyeGeneric.mg.510bdd4b3eef55b0
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.42834385
CrowdStrikewin/malicious_confidence_80% (D)
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34098.OKW@aWkwGofG
SymantecRansom.Nemty
Paloaltogeneric.ml
GDataWin32.Packed.Kryptik.8LR0RQ
KasperskyTrojan-Banker.Win32.Danabot.eda
APEXMalicious
Ad-AwareTrojan.GenericKD.42834385
SophosMal/RyPack-A
McAfee-GW-EditionBehavesLike.Win32.PUPXEI.jc
Trapminemalicious.moderate.ml.score
SentinelOneDFI – Suspicious PE
MAXmalware (ai score=85)
Endgamemalicious (high confidence)
ZoneAlarmTrojan-Banker.Win32.Danabot.eda
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Trojan/Win32.MalPe.R328190
Acronissuspicious
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HBUW
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgX58ox9HJAhbQ)
FortinetW32/Kryptik.HBNS!tr
PandaTrj/GdSda.A
Qihoo-360HEUR/QVM10.1.CC0B.Malware.Gen

How to remove Win32/Kryptik.HBUW?

Win32/Kryptik.HBUW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment