Malware

Win32/Kryptik.HECM removal guide

Malware Removal

The Win32/Kryptik.HECM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HECM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.HECM?


File Info:

name: B9D68F62192A96A871C1.mlw
path: /opt/CAPEv2/storage/binaries/06ef8ea8d36a563b776abc2f9c7e52ecfae68a6074e9abbde0d3a9fcc851a123
crc32: F72C587E
md5: b9d68f62192a96a871c1a47f33f42160
sha1: 29a6da7581d8bf0fe5b3d58e9711a5dd0555c9b8
sha256: 06ef8ea8d36a563b776abc2f9c7e52ecfae68a6074e9abbde0d3a9fcc851a123
sha512: 89a5cfe4b658e75d2b79e2b0af01248eb2729d33fb289cdd5ceb16fb86650396593effb40c2c7b0b36bf96d4573e579fed40d1533c4514ea303977c5cd20d535
ssdeep: 24576:KMt3ndAOO4oOs3GkaQJspjpd0BbDVdY+4IR+vsthD:fRfsNaQJUoLY+4nvstt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143052323A4073543F76588B44CB99546EE0F6B148B130D87DE6A28BD8BBD3D04B3E766
sha3_384: e9e12054e6580646fd277f1c6f4b3ba67872370f1e2fd71c596fd0cecf0612f456e812bc1cf1e2856a73aa21cd19156c
ep_bytes: 60be00d095008dbe0040aaffc787d069
timestamp: 2011-07-27 19:08:34

Version Info:

CompanyName: AVG Software Development Team
FileDescription: Abpwuiooofbjtjbwojweqixujtuchy
FileVersion: 1.5.13.36
LegalCopyright: © XAZUBV Software
ProductName: Tqx
ProductVersion: 1.5.13.36
Translation: 0x001b 0x04b0

Win32/Kryptik.HECM also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FakeAV.4!c
MicroWorld-eScanGen:Heur.VIZ.2
FireEyeGeneric.mg.b9d68f62192a96a8
CAT-QuickHealRogue.FakeRean
ALYacGen:Heur.VIZ.2
MalwarebytesMalware.Heuristic.1003
VIPREGen:Heur.VIZ.2
SangforTrojan.Win32.Kryptik.HECM
K7AntiVirusTrojan ( 0028a9fd1 )
AlibabaTrojan:Win32/Kryptik.b0287503
K7GWTrojan ( 0028a9fd1 )
Cybereasonmalicious.2192a9
BitDefenderThetaAI:Packer.E6B01ADC21
CyrenW32/Ransom.O.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HECM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.Fakealert.fvdkl
SUPERAntiSpywareTrojan.Agent/Gen-RogueAS
AvastWin32:FakeAlert-AVE [Trj]
TencentWin32.Trojan.Generic.Qzfl
EmsisoftGen:Heur.VIZ.2 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Fakealert.22273
ZillyaTrojan.FakeAV.Win32.119722
TrendMicroMal_FakeCon3
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cc
Trapminesuspicious.low.ml.score
SophosTroj/FakeAV-EGZ
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.VIZ.2
JiangminTrojan/Generic.iowq
WebrootW32.Rogue.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLHackTool[Hoax]/Win32.FakeAlert
XcitiumTrojWare.Win32.Kryptik.QIA@43at63
ArcabitTrojan.VIZ.2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRogue:Win32/FakeRean
GoogleDetected
AhnLab-V3Win-Trojan/FakeAV61.Gen
Acronissuspicious
McAfeeFakeAV-Rena.dk
MAXmalware (ai score=100)
VBA32BScope.Trojan.FakeAlert
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallMal_FakeCon3
RisingRansom.Trasbind!8.292E (TFE:5:6rOOIioYLZS)
YandexTrojan.Kryptik!0nRw1N5sAcI
IkarusTrojan.Win32.FakeAV
FortinetW32/FakeAlert.RENA!tr
AVGWin32:FakeAlert-AVE [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Win32/Kryptik.HECM?

Win32/Kryptik.HECM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment