Malware

Win32/Kryptik.HEDU removal

Malware Removal

The Win32/Kryptik.HEDU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HEDU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Win32/Kryptik.HEDU?


File Info:

crc32: D440E303
md5: c12fe969bc45cacecbaeb7e605001230
name: tmp9vgtqk5i
sha1: 73c90f177d6135faddddc9b570342696276eee6b
sha256: 81d264577a5de192e7ef08f94ede5f495cf2a39a39b62c094c9c5bc58c872d43
sha512: eeaa81a6405b9f9c34deeef9925e43ab42df8181f3dd12a4868507abe1b874a1306d6550abf47b4d5ffa86f3490ad62fe3d0a12b2cc043ba4773eddd3faed836
ssdeep: 6144:ZK6cDbMSq/ctw0jiTMn0juwTGJW9MAmwC5zAh8hsvsCIj9czyQuOY9Ej/7zfs19:ZK6cDwenEuYKWSwsA0CASlAE1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: osf3xswgesv.ixi
FileVersionOld: 1.2.0.1
ProductVersion: 1.0.4.1
Copyrighd: Copyrighd (C) 2020, odfgbiv
Translation: 0x0842 0x04c4

Win32/Kryptik.HEDU also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.43355497
FireEyeGeneric.mg.c12fe969bc45cace
ALYacTrojan.GenericKD.43355497
CylanceUnsafe
AegisLabTrojan.Win32.Scrop.b!c
SangforMalware
K7AntiVirusTrojan ( 00568ef31 )
BitDefenderTrojan.GenericKD.43355497
K7GWTrojan ( 00568ef31 )
Cybereasonmalicious.77d613
Invinceaheuristic
F-ProtW32/Wacatac.BV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Generic-8119045-0
GDataTrojan.GenericKD.43355497
KasperskyTrojan-Dropper.Win32.Scrop.acvh
AlibabaTrojanDropper:Win32/Scrop.0536ca14
TencentWin32.Trojan-dropper.Scrop.Sunn
Ad-AwareTrojan.GenericKD.43355497
EmsisoftTrojan.GenericKD.43355497 (B)
TrendMicroTROJ_GEN.R002C0DFI20
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Menti
CyrenW32/Wacatac.BV.gen!Eldorado
MAXmalware (ai score=84)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2958D69
ZoneAlarmTrojan-Dropper.Win32.Scrop.acvh
MicrosoftTrojan:Win32/DanaBot.AT!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Danabot.R340798
Acronissuspicious
McAfeePacked-GBO!C12FE969BC45
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HEDU
TrendMicro-HouseCallTROJ_GEN.R002C0DFI20
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.HEDU!tr
BitDefenderThetaGen:NN.ZexaF.34128.JC0@auNFu5bc
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Dropper.e0d

How to remove Win32/Kryptik.HEDU?

Win32/Kryptik.HEDU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment