Malware

What is “Win32/Kryptik.HEEW”?

Malware Removal

The Win32/Kryptik.HEEW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HEEW virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

a.tomx.xyz

How to determine Win32/Kryptik.HEEW?


File Info:

crc32: 0AA712C7
md5: 6d0f58515e8c82a3618b7a0dec770962
name: se.jpg
sha1: 922e997c250a47b6d19df17886110d33578c97ff
sha256: 371abcd798cd0c9eeadcda50c04ca046db10042e22dd2742b0510497e50b8003
sha512: c9bb0b5713b6551a38534f5e1e0da27a0119eea761e39ca5fe61e57c4b4cd3109b5b29499a3355a67f2d32307ea0cadb552bea46d67943afcadd5a9d183c5305
ssdeep: 3072:aWgjTCGNPMjrjKJ0vAnwcCylqVbn5XPMxLssyAixVBJ5xcIwOFxPZNhXHbd:aW4tEPGJ0vwC1V1tsyAOBJ51wINbd
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: taskhostex.exe
FileVersion: 6.3.9600.17415 (winblue_r4.141028-1500)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.3.9600.17415
FileDescription: Host Process for Windows Tasks
OriginalFilename: taskhostex.exe
Translation: 0x0804 0x04b0

Win32/Kryptik.HEEW also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.43360986
FireEyeGeneric.mg.6d0f58515e8c82a3
CAT-QuickHealTrojan.Multi
McAfeeRDN/Generic.rp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 00569e0e1 )
BitDefenderTrojan.GenericKD.43360986
K7GWTrojan ( 00569e0e1 )
Cybereasonmalicious.c250a4
ArcabitTrojan.Generic.D295A2DA
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34144.lu1@aingh@bj
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HEEW
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPFK20
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Kryptik.83eeedee
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.43360986
EmsisoftTrojan.GenericKD.43360986 (B)
F-SecureHeuristic.HEUR/AGEN.1116853
ZillyaTrojan.Kryptik.Win32.2052688
TrendMicroTrojan.Win32.WACATAC.USXVPFK20
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.QOGW-2270
JiangminTrojanDownloader.Generic.bccg
AviraHEUR/AGEN.1116853
FortinetW32/Kryptik.HEEW!tr
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Occamy.C37
ZoneAlarmUDS:DangerousObject.Multi.Generic
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4156479
Acronissuspicious
VBA32Trojan.Wacatac
ALYacTrojan.GenericKD.43360986
MAXmalware (ai score=86)
MalwarebytesTrojan.Agent
PandaTrj/GdSda.A
APEXMalicious
TencentWin32.Trojan.Miner.Jhbc
YandexTrojan.Kryptik!6lV12Ym8/Zo
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKD.43360986
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HEEW?

Win32/Kryptik.HEEW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment