Malware

Win32/Kryptik.HFLY removal tips

Malware Removal

The Win32/Kryptik.HFLY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFLY virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HFLY?


File Info:

crc32: 77BDB3A3
md5: c7483b512ca185d3119192a208fa20b4
name: upload_file
sha1: ad05a0d8ace5406462ae85e34be7e2312af20371
sha256: ffcec4984a2f2592b1f5bb2bf316a232f78b6c22b8d0a7d957ce1af0d098f904
sha512: d6399d2d3d0c468424644fb9ee734b3587781061ab971bf820fa5e3b23420c6911779b85ceae10392c2a8704c0e1403a918c9d77d7e776df9dfff0d79d2edeaf
ssdeep: 12288:Ogu9dxtqrDutMCVFy79ZbWtpfd/WIzmrsB7wF8M3xIrqFAJTiIsJIMEJS:DKXqPh579std2rC7wF8ezrynJ
type: # UDF filesystem data (version 1.5) 'PAYMENT'

Version Info:

0: [No Data]

Win32/Kryptik.HFLY also known as:

McAfeeArtemis!A636C86DBB71
SangforMalware
Invinceaheuristic
ESET-NOD32a variant of Win32/Kryptik.HFLY
TrendMicro-HouseCallPossible_GENISO-6
CynetMalicious (score: 85)
RisingTrojan.GenKryptik!8.AA55 (TFE:dGZlOgWSDZBrDZVGZg)
F-SecureHeuristic.HEUR/AGEN.1103328
DrWebTrojan.Inject3.50148
TrendMicroPossible_GENISO-6
IkarusTrojan.MSIL.Crypt
AviraHEUR/AGEN.1103328
FortinetW32/Kryptik.HFID!tr
MicrosoftTrojan:Win32/Woreflint.A!cl
VBA32BScope.TrojanPSW.MSIL.Agensla
BitDefenderThetaGen:NN.ZexaF.34152.JyW@aKY33Ooi

How to remove Win32/Kryptik.HFLY?

Win32/Kryptik.HFLY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment