Malware

About “Win32/Kryptik.HDPV” infection

Malware Removal

The Win32/Kryptik.HDPV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HDPV virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HDPV?


File Info:

crc32: 56015B1C
md5: 0420435e01b432b69af26314d6faa99d
name: 0420435E01B432B69AF26314D6FAA99D.mlw
sha1: 8158678ae1757f7d2cd28d8b5216ec42fad4fbc9
sha256: 389ddb82e254c476a6e3e2534182314d4702ce525371c2bcd5da6ef19d4851fb
sha512: 9c586c3ab5f295bde02fe5ad4029a8dcdfb831278d15f47ee38018d8aa3f90ed27c97e3e5c15ed662fe9dc8c77dea0e5ec055cd7e538b3f91b366a6ab3455045
ssdeep: 24576:D18sIbgCL4R3/U+9OA5VSl4NsD4ou1w9tvTL:R8DbpL8vp9OO6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2001
InternalName: ColorPickerDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ColorPickerDemo x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: ColorPickerDemo Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: ColorPickerDemo.EXE
Translation: 0x0804 0x04b0

Win32/Kryptik.HDPV also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36447029
FireEyeGeneric.mg.0420435e01b432b6
CAT-QuickHealBackdoor.Farfli
McAfeeGenericRXLN-YN!0420435E01B4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00567b521 )
BitDefenderTrojan.GenericKD.36447029
K7GWTrojan ( 00567b521 )
Cybereasonmalicious.e01b43
BitDefenderThetaGen:NN.ZexaF.34608.sr0@aO46sMgb
CyrenW32/Kryptik.CAS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HDPV
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Dropper.Zegost-9837515-0
KasperskyBackdoor.Win32.Farfli.bsce
AlibabaBackdoor:Win32/Farfli.290461f6
NANO-AntivirusTrojan.Win32.Farfli.hukckh
ViRobotTrojan.Win32.Z.Farfli.1347584.A
AegisLabTrojan.Win32.Farfli.m!c
TencentMalware.Win32.Gencirc.11ba5f6f
Ad-AwareTrojan.GenericKD.36447029
EmsisoftTrojan.Crypt (A)
ComodoMalware@#31nutz8hbqifv
F-SecureHeuristic.HEUR/AGEN.1134997
DrWebTrojan.DownLoader33.52941
ZillyaTrojan.Kryptik.Win32.2320042
TrendMicroBackdoor.Win32.FARFLI.THBBCBA
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
SophosMal/Generic-S
IkarusBackdoor.Win32.Zegost
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1134997
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:Win32/Zegost.KM!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D22C2335
AhnLab-V3Malware/Win32.RL_Generic.R358854
ZoneAlarmBackdoor.Win32.Farfli.bsce
GDataTrojan.GenericKD.36447029
CynetMalicious (score: 100)
VBA32BScope.Backdoor.Farfli
ALYacTrojan.GenericKD.36447029
MalwarebytesMalware.AI.3001678374
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.Win32.FARFLI.THBBCBA
RisingTrojan.Kryptik!1.C71D (CLOUD)
YandexBackdoor.Farfli!JJritEMmL/Q
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HDPV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.Zegost.HwcBd9sA

How to remove Win32/Kryptik.HDPV?

Win32/Kryptik.HDPV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment