Malware

Win32/Kryptik.HFIC removal

Malware Removal

The Win32/Kryptik.HFIC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFIC virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (5 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Win32/Kryptik.HFIC?


File Info:

crc32: 5E18C2A1
md5: 27b3505111c29a568f026580b1d9b9a7
name: wusa.exe
sha1: 1cfaa304dc0e97bca87a784e68720452dc01b763
sha256: 02c0c7088e77cb847deeb1d76144509e14fc22865b5302060375b6d72b10c751
sha512: 92ef592b85bfb250380f8aeeef47ac981f5424864ee4cde09b0d02b586ef455e03eb977025f01c7da052d76de2af7cd1ee87f23ad75cc459edac3f36f735da50
ssdeep: 24576:FtiDqzL46VDAFWEbCQOitJ9kOfZytLt+cI:Fz0I0N2QOVOZytscI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009-11, 2015 Dave Brotherstone
InternalName: gpup
FileVersion: 1.3.5.0
Comments: A generic(ish) plugin ipdater, built initially for Notepad++
ProductName: gpup
ProductVersion: 1.3.5.0
FileDescription: gpup
OriginalFilename: gpup.exe
Translation: 0x0809 0x04b0

Win32/Kryptik.HFIC also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34275095
FireEyeGeneric.mg.27b3505111c29a56
McAfeeGenericRXLO-VR!27B3505111C2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056bcff1 )
BitDefenderTrojan.GenericKD.34275095
K7GWTrojan ( 0056bcff1 )
Cybereasonmalicious.111c29
TrendMicroTROJ_FRS.0NA104H220
SymantecTrojan!im
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyTrojan.Win32.Injuke.lgx
AlibabaTrojan:Win32/Injuke.b641d996
TencentWin32.Trojan.Injuke.Hssp
Ad-AwareTrojan.GenericKD.34275095
SophosMal/EncPk-APV
F-SecureTrojan.TR/AD.StellarStealer.mljed
DrWebTrojan.PWS.Siggen2.51569
Invinceaheuristic
FortinetW32/GenKryptik.EOOB!tr
EmsisoftTrojan.GenericKD.34275095 (B)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
AviraTR/AD.StellarStealer.mljed
MAXmalware (ai score=84)
Antiy-AVLTrojan[Downloader]/Win32.Deyma
ArcabitTrojan.Generic.D20AFF17
ZoneAlarmTrojan.Win32.Injuke.lgx
MicrosoftTrojan:Win32/Raccoonstealer!cert
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R346657
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34152.2y1@aG8a6vji
ALYacTrojan.GenericKD.34275095
VBA32TrojanPSW.Racealer
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFIC
TrendMicro-HouseCallTROJ_FRS.0NA104H220
RisingMalware.Heuristic!ET#78% (RDMK:cmRtazq4wdVLE0KxFKaTS+PGXqcu)
SentinelOneDFI – Suspicious PE
GDataTrojan.GenericKD.34275095
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.a4a

How to remove Win32/Kryptik.HFIC?

Win32/Kryptik.HFIC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment