Malware

Win32/Kryptik.HFGV information

Malware Removal

The Win32/Kryptik.HFGV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFGV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

www.intel.com
help.twitter.com
support.oracle.com
support.apple.com
loadbudapest.casa

How to determine Win32/Kryptik.HFGV?


File Info:

crc32: 41EC7E3D
md5: a1bb6b79c748c063eb912e06a136a991
name: upload_file
sha1: 79d171d0730091a0c0df16c91a1ca95f5129a5b6
sha256: 202e93ce45541da3971aebc5ec5027209ab9ce01cfd65e229ecf90d396b8201d
sha512: 686b79358421fb81d4b3d1b4d6268b24e4e0202c885f87342248ba05eafbd21691c99634de9d1f52dd515d1e0af0ea17ac734129f618bbe181cf6675243394b0
ssdeep: 3072:6KBxXLIOI4Bg6YJdC1ZxZgpARBk+ltNuVH4:6wxCJA8sB3tgY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HFGV also known as:

MicroWorld-eScanTrojan.GenericKD.34262900
FireEyeGeneric.mg.a1bb6b79c748c063
CAT-QuickHealTrojan.Multi
McAfeeRDN/PWS-Banker
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
K7AntiVirusTrojan ( 0056ba501 )
BitDefenderTrojan.GenericKD.34262900
K7GWTrojan ( 0056ba501 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.34262900
KasperskyTrojan-Banker.Win32.IcedID.twoi
AlibabaTrojanBanker:Win32/IcedID.37348287
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.34262900 (B)
F-SecureTrojan.TR/AD.PhotoDlder.azmja
DrWebTrojan.IcedID.30
TrendMicroTROJ_GEN.R002C0DGV20
MaxSecureWin.MxResIcn.Heur.Gen
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
JiangminTrojan.Banker.IcedID.nz
WebrootW32.Trojan.Gen
AviraTR/AD.PhotoDlder.azmja
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/IcedId.DAX!MTB
ArcabitTrojan.Generic.D20ACF74
ZoneAlarmTrojan-Banker.Win32.IcedID.twoi
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Agent.R346572
ALYacTrojan.IcedID.Gen
Ad-AwareTrojan.GenericKD.34262900
MalwarebytesTrojan.MalPack.RND
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFGV
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
RisingTrojan.Kryptik!8.8 (CLOUD)
BitDefenderThetaGen:NN.ZedlaF.34144.ku5@a4vY1rc
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.b04

How to remove Win32/Kryptik.HFGV?

Win32/Kryptik.HFGV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment