Malware

Win32/Kryptik.HBZR (file analysis)

Malware Removal

The Win32/Kryptik.HBZR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBZR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Detects SunBelt Sandbox through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tldrbox.top

How to determine Win32/Kryptik.HBZR?


File Info:

crc32: 0BFAB824
md5: 61c33d015983d06570ff7f7300c551e2
name: 64.exe
sha1: 29998990a7d301eb11e6e0c86cf81d15e3e4b0c0
sha256: 993d2f33be65ced84cdcaff1e57616a80f708ecfacb6f7b12c94aa65e121f080
sha512: a73de3556ac97f06cd61a95e3ba05ec85de492bab3010122ba1ad6794bc64865bc62d7b3287e650f4d4db40e4ae2049458213111fbed5a4f252da3c78c8192da
ssdeep: 1536:CMjf39BL7mI9iTf6NiVckp2oZIfnLQ7iRcVxXW+d1mQ9Lj+NVA5jDKPrv/g14ND:FHL71JiVY5n0mROpbx1joC5j+PM1CDZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HBZR also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33552839
FireEyeGeneric.mg.61c33d015983d065
McAfeeArtemis!61C33D015983
SangforMalware
K7AntiVirusTrojan ( 00562e241 )
BitDefenderTrojan.GenericKD.33552839
K7GWTrojan ( 00562e241 )
Cybereasonmalicious.0a7d30
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34100.juW@aiMv31t
CyrenW32/Trojan.LQAJ-8220
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBZR
TrendMicro-HouseCallTROJ_GEN.R002C0DCI20
AvastWin32:CoinminerX-gen [Trj]
GDataTrojan.GenericKD.33552839
KasperskyTrojan-Banker.Win32.CliptoShuffler.azf
AlibabaTrojan:Win32/Starter.ali2000005
NANO-AntivirusTrojan.Win32.CliptoShuffler.hfgxal
AegisLabTrojan.Win32.Malicious.4!c
APEXMalicious
Ad-AwareTrojan.GenericKD.33552839
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Phorpiex.wmsgb
DrWebTrojan.Siggen9.21890
TrendMicroTROJ_GEN.R002C0DCI20
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.ch
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33552839 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan/Swizzor.ggv
WebrootW32.Trojan.Gen
AviraTR/AD.Phorpiex.wmsgb
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.RanumBot
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFF9C7
AhnLab-V3Trojan/Win32.MalPe.R329073
ZoneAlarmTrojan-Banker.Win32.CliptoShuffler.azf
MicrosoftTrojan:Win32/RanumBot.GA!MTB
Acronissuspicious
ALYacTrojan.Agent.Phorpiex
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan-Downloader.Win32.Zurgop
FortinetW32/Kryptik.HBYA!tr
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.a61

How to remove Win32/Kryptik.HBZR?

Win32/Kryptik.HBZR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment