Malware

Should I remove “Win32/Kryptik.HGSK”?

Malware Removal

The Win32/Kryptik.HGSK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGSK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
support.apple.com
help.twitter.com
ldrpeset.casa
www.intel.com
support.oracle.com

How to determine Win32/Kryptik.HGSK?


File Info:

crc32: 25BD423E
md5: bcfc0b44af8595fa96d65e99a162aa54
name: upload_file
sha1: ca4e1439ee72b82d31ac348c805d4d87c1622fd7
sha256: aee6295dab6fd012e5bd1ee352317e56bef5789e2e83e7d5cc743161cedd957b
sha512: b1d8fac11f0470aeb20f6c520e5f5f087eba5c1c691a1dbb24dd2a3f1c44981a9488d3964481c2cf3c74fd3e9e243b5f2f0c7ee0418c60f35c1f787ce1e3a54e
ssdeep: 3072:210VWHcpNwEd1XY2bsxiRpACbyR7gbFem5:fWHcpNfdxhwxKNem5
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2018 Minutehave Corporation. All rights reserved.
InternalName: full.dll
FileVersion: 6.5.5.597
CompanyName: Minutehave
ProductName: Minutehave Reply fair
OriginalFilename: full.dll
Translation: 0x0409 0x04b0

Win32/Kryptik.HGSK also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.44072077
Qihoo-360Win32/Trojan.0f5
McAfeeArtemis!BCFC0B44AF85
MalwarebytesTrojan.IcedID
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.IcedID.7!c
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.44072077
K7GWTrojan ( 005710db1 )
K7AntiVirusTrojan ( 005710db1 )
ArcabitTrojan.Generic.D2A07C8D
InvinceaMal/Generic-S
SymantecTrojan Horse
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.IcedID.gen
AlibabaTrojanBanker:Win32/IcedId.5da56c78
RisingTrojan.Generic@ML.86 (RDML:WDk4+g6DeDdV9MtO/WPdyQ)
Ad-AwareTrojan.GenericKD.44072077
EmsisoftTrojan.GenericKD.44072077 (B)
ComodoMalware@#mp2l6l94j9ye
F-SecureTrojan.TR/AD.PhotoDlder.gcxhk
McAfee-GW-EditionArtemis!Trojan
SentinelOneDFI – Suspicious PE
FireEyeGeneric.mg.bcfc0b44af8595fa
SophosMal/Generic-S
APEXMalicious
AviraTR/AD.PhotoDlder.gcxhk
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/IcedId.AR!MTB
ZoneAlarmHEUR:Trojan-Banker.Win32.IcedID.gen
GDataWin32.Trojan.Agent.YAE1O2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.R353146
ALYacTrojan.IcedID.gen
ESET-NOD32a variant of Win32/Kryptik.HGSK
IkarusTrojan.SuspectCRC
FortinetW32/PhotoDlder.RDOA!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
MaxSecureTrojan.Malware.12162265.susgen

How to remove Win32/Kryptik.HGSK?

Win32/Kryptik.HGSK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment