Malware

Win32/Kryptik.HDHE removal instruction

Malware Removal

The Win32/Kryptik.HDHE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HDHE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tamil
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HDHE?


File Info:

crc32: 46D11298
md5: 5d164f65a5e608fd98f13e6b91773d11
name: 5D164F65A5E608FD98F13E6B91773D11.mlw
sha1: 5a82b6d8a3bcc13350c6ae7696749645b6fcc1dd
sha256: ee422cf7e224d0f47f5e3f8aec76044589c76b0d19506da0bfa8f403b531ccad
sha512: a97404b55b237e5bf4ccbcdaa9bcbcf41b806d9769e0b8d861b377386409cc5958ac4ea2ee01fd1d71bb234df4ecb0e2b7f8c4d49104f6f6623810580a25d74b
ssdeep: 3072:P0mw6LEWLI4kWVqrxPLOvR6vhrjhUeWl9rmdZfcz05T5LsWSAReXU54Yra:n7QWLvkuq9jOvMpRUegNUFcz05T2b5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyrighd: Copyrighd (C) 2020, jlfvjz
InternalName: xyaveshu.izi
FileVersionBeer: 1.3.3.4
ProductVersion: 1.7.54

Win32/Kryptik.HDHE also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056809d1 )
LionicTrojan.Win32.Gen.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31809
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Sodinokibi
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0056689f1 )
Cybereasonmalicious.5a5e60
CyrenW32/Kryptik.FIQ.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HDHE
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Ransomware.Tofsee-9755254-0
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
BitDefenderGen:Heur.Mint.Zard.52
NANO-AntivirusTrojan.Win32.Encoder.hkeeie
MicroWorld-eScanGen:Heur.Mint.Zard.52
TencentWin32.Backdoor.Tofsee.Swbe
Ad-AwareGen:Heur.Mint.Zard.52
SophosML/PE-A + Mal/GandCrab-G
ComodoMalware@#2aotqwq5ivnyu
BitDefenderThetaGen:NN.ZexaF.34236.sq0@aGdd21cG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
FireEyeGeneric.mg.5d164f65a5e608fd
EmsisoftGen:Heur.Mint.Zard.52 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.xvhvn
Antiy-AVLTrojan/Generic.ASMalwS.306F478
MicrosoftRansom:Win32/Gandcrab.AHB!MTB
ArcabitTrojan.Mint.Zard.52
GDataGen:Heur.Mint.Zard.52
AhnLab-V3Trojan/Win.MalPe.X2065
Acronissuspicious
McAfeePacked-GBE!5D164F65A5E6
MAXmalware (ai score=100)
VBA32TrojanRansom.Gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.C6C5 (CLASSIC)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ELQV!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HDHE?

Win32/Kryptik.HDHE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment