Malware

Win32/Kryptik.HFDI removal

Malware Removal

The Win32/Kryptik.HFDI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFDI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bing.com

How to determine Win32/Kryptik.HFDI?


File Info:

crc32: 2CA5DFA7
md5: ca1380d96f48aac83c9bb24390dbb637
name: jjj.exe
sha1: 0662fb1bd20bad308917f2164e1f3d0e0a47ce8a
sha256: c4d2ef8402f6b01213346d603158c0c0d91b69e73006a1b0f8e85fcb4cc27615
sha512: 5accef3bc9f442222228293a019c4fe822b6578df8d9419516374577ca8526dd0b470c68d4ca9fe6a363a9bd8dd15aeeefa9d613568c91e369727feecd9ed045
ssdeep: 3072:Me0SIhB51dRqmGc56pR28L+45cYblRp39TO+eGq:MUIhBPzP5kzE6Xlel
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: hzrj.uxe
ProductionVersus: 1.0.6.22
Copyrights: Copyrighd (C) 2020, sdgfsd
FileV: 1.0.1
TranslationUsi: 0x0872 0x0509

Win32/Kryptik.HFDI also known as:

FireEyeGeneric.mg.ca1380d96f48aac8
MalwarebytesSpyware.Arkei
SangforMalware
K7GWHacktool ( 700007861 )
Cybereasonmalicious.bd20ba
Invinceaheuristic
F-ProtW32/Kryptik.BRD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
IkarusTrojan.Win32.Ranumbot
CyrenW32/Kryptik.BRD.gen!Eldorado
MicrosoftTrojan:Win32/Caynamer.A!ml
Endgamemalicious (high confidence)
ZoneAlarmUDS:DangerousObject.Multi.Generic
CynetMalicious (score: 100)
Acronissuspicious
CylanceUnsafe
ESET-NOD32a variant of Win32/Kryptik.HFDI
RisingTrojan.Kryptik!8.8 (TFE:dGZlOgU5ItMvmcEgxg)
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.HEZN!tr
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM10.1.D4FB.Malware.Gen

How to remove Win32/Kryptik.HFDI?

Win32/Kryptik.HFDI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment