Malware

Win32/Kryptik.HDSP removal guide

Malware Removal

The Win32/Kryptik.HDSP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HDSP virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Tunisia)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HDSP?


File Info:

crc32: 6E48B127
md5: 06b6bc540b94245a836878d07bbba5b6
name: art.exe
sha1: e28490a9eb4e3b88e008fe7c42bf4e0ae3853c86
sha256: b6fdb7faa5d446e8dea142f089550d2430320d4024415278bf4362df46a091b0
sha512: 6ded2049c0c1a14cf03e4ac3d66b78c48181bfdec9e0ec162f54a6ff9fcac25c164717e6e5faa859af77aa8a60abc57b98e5bb8deac6fd7a7ab82f461ebd2f5c
ssdeep: 1536:pM9JITx0vz8NKLP3sZoNPHzFOkuSwd0wRPqAMLBevps73Sp4:pMINuz8m8ZoNrFOk7Cp0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020, kilu
InternalName: awizegpoz.im
Translations: 0x0441 0x0315

Win32/Kryptik.HDSP also known as:

MicroWorld-eScanTrojan.GenericKD.43255980
FireEyeGeneric.mg.06b6bc540b94245a
McAfeeRDN/Generic.grp
CylanceUnsafe
AegisLabTrojan.Win32.FraudPack.kYX5
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.43255980
K7GWTrojan ( 00567c201 )
K7AntiVirusTrojan ( 00567c201 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.43255980
KasperskyExploit.Win32.Shellcode.qin
AlibabaTrojan:Win32/Shellcode.3df2ee40
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.43255980 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R011C0DF120
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
AviraTR/AD.MalwareCrypter.bture
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Obfuscator.PD!MTB
ArcabitTrojan.Generic.D29408AC
ZoneAlarmExploit.Win32.Shellcode.qin
AhnLab-V3Trojan/Win32.MalPe.R338768
Acronissuspicious
ALYacTrojan.GenericKD.43255980
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HDSP
TrendMicro-HouseCallTROJ_GEN.R011C0DF120
FortinetW32/GenKryptik.ELND!tr
Ad-AwareTrojan.GenericKD.43255980
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Exploit.03d

How to remove Win32/Kryptik.HDSP?

Win32/Kryptik.HDSP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment