Malware

Should I remove “Win32/Kryptik.HGFG”?

Malware Removal

The Win32/Kryptik.HGFG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGFG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.

How to determine Win32/Kryptik.HGFG?


File Info:

crc32: AAF911A4
md5: e33bcb9fb37c5cddce99a0b79a1dce1f
name: E33BCB9FB37C5CDDCE99A0B79A1DCE1F.mlw
sha1: 09847d3c4998765b1afeb56d764c5076b9d4f79f
sha256: 58801d89d261d80e9545902632bcaa5cfd8554c92d728f0b278aefbff755857d
sha512: 466b72c947e73832a67ed738dfb8481d07663069d55977d1919d32e9379d00ea9eee842230b79645370452b9a6fe27daa882012e204645f0b696ca1453022da5
ssdeep: 3072:JprlfdVbSzZeF7GnZKKRkjf48AoerQBgQN0jT2t2ue2TlrInP+kb5P7j9:LrllVuqGnZ58f1eegUA2tVe2Tx6PFN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2003 Hans Dietrich
FileVersion: 1, 0, 0, 1
ProductName: XCharMapTest
E-mail: hdietrich2@hotmail.com
ProductVersion: 1, 0, 0, 1
FileDescription: XCharMapTest.exe
OriginalFilename: XCharMapTest.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.HGFG also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.46720
MicroWorld-eScanTrojan.EmotetU.Gen.oq0@dmhIM@pi
FireEyeTrojan.EmotetU.Gen.oq0@dmhIM@pi
McAfeeEmotet-FRM!E33BCB9FB37C
K7AntiVirusTrojan ( 005605291 )
BitDefenderTrojan.EmotetU.Gen.oq0@dmhIM@pi
K7GWTrojan ( 005605291 )
TrendMicroTrojanSpy.Win32.EMOTET.SMD4.hp
CyrenW32/Wacatac.CC.gen!Eldorado
SymantecPacked.Generic.554
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Emotet-9762316-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.pef
Ad-AwareTrojan.EmotetU.Gen.oq0@dmhIM@pi
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
EmsisoftTrojan.Emotet (A)
MaxSecureTrojan.Malware.121218.susgen
MicrosoftTrojan:Win32/Emotet.ARK!MTB
ArcabitTrojan.EmotetU.Gen.E32F5D
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.pef
GDataTrojan.EmotetU.Gen.oq0@dmhIM@pi
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C4197396
ALYacTrojan.EmotetU.Gen.oq0@dmhIM@pi
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HGFG
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMD4.hp
RisingHackTool.CeeInject!8.B22 (TFE:3:lnKB9NnxARL)
IkarusTrojan-Banker.Emotet
eGambitUnsafe.AI_Score_63%
FortinetW32/GenericKDZ.7014!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM20.1.38DF.Malware.Gen

How to remove Win32/Kryptik.HGFG?

Win32/Kryptik.HGFG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment