Malware

About “Win32/Kryptik.HFNX” infection

Malware Removal

The Win32/Kryptik.HFNX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFNX virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HFNX?


File Info:

crc32: 230D49BE
md5: 79250ea705ee3b68e3f60a577195c8a9
name: upload_file
sha1: d2afff7369f8bbe050b6e2c95e92e6e43ea187b1
sha256: 701ebb977344e0a8dbb13ceeb5096a3ea22605cb48f1f1d5aa0fbddaf251402a
sha512: aac27ee8cb2f8dc91f16b20d11c74ec4434979b95648a619851f478cfd5473eb6cd04c0099f951d48a182118be60261326f7c2d6edfdd359d9eb202c8f8e1964
ssdeep: 6144:vevXjvYLziOVAdY+ZIJ+IryMBFecmfGPgir:GrvYKsqeTaG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersiones: 1.0.0.1
Copyright: Copyright (C) 2020, hotc
Translations: 0x0192 0x03d8

Win32/Kryptik.HFNX also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.18411
MicroWorld-eScanTrojan.GenericKD.43679503
FireEyeGeneric.mg.79250ea705ee3b68
ALYacTrojan.GenericKD.43679503
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0056c87f1 )
BitDefenderTrojan.GenericKD.43679503
K7GWTrojan ( 0056c87f1 )
Cybereasonmalicious.369f8b
TrendMicroTROJ_GEN.R032C0DHI20
BitDefenderThetaGen:NN.ZexaF.34186.nqW@aC8XGzaG
CyrenW32/Trojan.PWAS-5756
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tofsee-9393128-0
KasperskyTrojan-PSW.Win32.Coins.yng
AlibabaTrojanPSW:Win32/Coins.d82d89a2
ViRobotTrojan.Win32.Z.Limpopo.226816
RisingTrojan.Kryptik!1.CABF (CLOUD)
Ad-AwareTrojan.GenericKD.43679503
F-SecureTrojan.TR/AD.MoksSteal.BD
ZillyaTrojan.Coins.Win32.5232
Invinceaheuristic
SophosMal/Generic-S
AviraTR/AD.MoksSteal.BD
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Stealer.VC!MTB
ArcabitTrojan.Generic.D29A7F0F
ZoneAlarmTrojan-PSW.Win32.Coins.yng
GDataTrojan.GenericKD.43679503
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R348326
Acronissuspicious
McAfeeArtemis!79250EA705EE
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HFNX
TrendMicro-HouseCallTROJ_GEN.R032C0DHI20
IkarusTrojan-Dropper.Win32.Danabot
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.HFNX!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.b00

How to remove Win32/Kryptik.HFNX?

Win32/Kryptik.HFNX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment