Malware

About “Win32/Kryptik.HEXN” infection

Malware Removal

The Win32/Kryptik.HEXN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HEXN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HEXN?


File Info:

crc32: 4BA94193
md5: 749fed47952f92de5d2f8cf9787681f2
name: 749FED47952F92DE5D2F8CF9787681F2.mlw
sha1: cf960abc6eec91cc72fe02587a60a7886e9742a4
sha256: 29b609278f521134ba87b4fb5379b341891662916e1967740ad0c4190b3a1a40
sha512: 8d87b71ef44cbd34d48069ba94899c8c890c88d946b41e4aa926a2402887d7f7d8ebc65766e4ccddea9e3a9bd609c31d998d33ac1e8b19fb2e06e94234330bf2
ssdeep: 12288:5Htj6KWCNbn/dZ89Ma+a4OJUBUTdIaIXM:ptjHNbnUyQJIUTdhIXM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2015
InternalName: SmartRAM
FileVersion: 9.0.0.22
CompanyName: IObit
LegalTrademarks: IObit
Comments: Smart RAM
ProductName: Smart RAM
ProductVersion: 9.0.0.0
FileDescription: Monitors and Optimizes memory usage to increase available physical memory.
OriginalFilename: SmartRAM.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.HEXN also known as:

K7AntiVirusTrojan ( 0054f2ec1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacTrojan.Mint.Zamg.O
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Cerber.110d57fe
K7GWTrojan ( 005114a51 )
Cybereasonmalicious.7952f9
CyrenW32/S-502d1467!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.HEXN
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Cerber-9760825-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Mint.Zamg.O
NANO-AntivirusTrojan.Win32.Zerber.ertepy
MicroWorld-eScanTrojan.Mint.Zamg.O
TencentMalware.Win32.Gencirc.10bb078b
Ad-AwareTrojan.Mint.Zamg.O
SophosML/PE-A + Mal/Cerber-AL
ComodoTrojWare.Win32.Bulta.GR@7k46qi
F-SecureHeuristic.HEUR/AGEN.1129194
BitDefenderThetaGen:NN.ZexaF.34608.Oq0@aaSKLQej
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SMALY5B
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
FireEyeGeneric.mg.749fed47952f92de
EmsisoftTrojan.Mint.Zamg.O (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129194
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftRansom:Win32/Cerber.L!bit
ArcabitTrojan.Mint.Zamg.O
AegisLabTrojan.Win32.Zerber.toYR
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.Cerber.AL
AhnLab-V3Win-Trojan/Cerber.Exp
Acronissuspicious
McAfeeRansomware-GCQ!749FED47952F
MAXmalware (ai score=100)
VBA32Hoax.Zerber
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPCERBER.SMALY5B
RisingTrojan.Kryptik!1.AD41 (CLASSIC)
YandexTrojan.GenAsa!eYKLWLGfpyo
IkarusTrojan.Win32.Filecoder
FortinetW32/Zamg.O!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBpgcA

How to remove Win32/Kryptik.HEXN?

Win32/Kryptik.HEXN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment