Malware

About “Win32/Kryptik.HEKP” infection

Malware Removal

The Win32/Kryptik.HEKP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HEKP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Finnish
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

advert127ds.xyz
adxspace147.xyz
api.ipify.org

How to determine Win32/Kryptik.HEKP?


File Info:

crc32: 4C99D302
md5: c611dfa322b179a3e82cd78e3c8f4ca9
name: socks777.exe
sha1: e2bd00085dec20c6bf22981f299a838a5b221351
sha256: 2000a32ad4e07b435995d624b4406ed34700f0754040a36ad3bbc8190f9c9495
sha512: 1c2b9c78a7928f38237a45f7b170309d9976052f93ded3b6e8560a18c59b873c608fb1c157c4d1bc7b152c81709e5639b784190806ea128edf90ec0d1419fcde
ssdeep: 3072:MvAmki4EoZ/Vvw8Ad/UfUVJFZG3XV4M6gXK/ksX7:MvN4bZ/VvMzJ/eXy91/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: amizepug.im
FileVersion: 1.0.0.1
Copyright: Copyright (C) 2020, kazosh
ProductVersion: 1.7.45
Translations: 0x0441 0x0315

Win32/Kryptik.HEKP also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.34071854
McAfeeGenericRXAA-AA!C611DFA322B1
SangforMalware
BitDefenderTrojan.GenericKD.34071854
K7GWTrojan ( 0056988f1 )
Cybereasonmalicious.85dec2
ArcabitTrojan.Generic.D207E52E
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HEKP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Injuke.fex
RisingTrojan.Injuke!8.10932 (CLOUD)
Ad-AwareTrojan.GenericKD.34071854
EmsisoftTrojan.Agent (A)
F-SecureTrojan.TR/AD.Coroxy.xehvt
Invinceaheuristic
FireEyeGeneric.mg.c611dfa322b179a3
IkarusTrojan.Win32.Crypt
AviraTR/AD.Coroxy.xehvt
eGambitUnsafe.AI_Score_78%
FortinetMalicious_Behavior.SB
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
MicrosoftRansom:Win32/SodinokibiCrypt.SK!MTB
ZoneAlarmTrojan.Win32.Injuke.fex
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R341637
Acronissuspicious
ALYacTrojan.GenericKD.34071854
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen
GDataTrojan.GenericKD.34071854
BitDefenderThetaGen:NN.ZexaF.34130.lq0@a8NW6xaG
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360HEUR/QVM10.1.29D3.Malware.Gen

How to remove Win32/Kryptik.HEKP?

Win32/Kryptik.HEKP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment