Malware

Should I remove “Win32/Kryptik.HGTJ”?

Malware Removal

The Win32/Kryptik.HGTJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGTJ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HGTJ?


File Info:

crc32: FF5EC87A
md5: 83a7e41f8879b5aeaf745ccd9610f3b0
name: ze0RJ3jht.exe
sha1: 46ea0ddf4e014210dc8e279404af601f26abbcc0
sha256: aeae67989c438a59fb0242409c87f0259ec87f04d3df661162c6a7540e7a1e8c
sha512: 253f10126b8d521108844a747d9763b205d5c149a35466bf9cc608c3425f21a3032325ff13ff5a35fbd0439da1a398ecab5fec3e0cbbf907f117d3d0c6282c8d
ssdeep: 6144:SMeVGThcCLoa1BsQNJSjog73p6ekMpIK4L+vMtMK:SOLDleog7YekMGDqv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004
InternalName: ColorBoxSample
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: ColorBoxSample Application
ProductVersion: 1, 0, 0, 1
FileDescription: ColorBoxSample MFC Application
OriginalFilename: ColorBoxSample.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HGTJ also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.70716
FireEyeGeneric.mg.83a7e41f8879b5ae
McAfeeArtemis!83A7E41F8879
BitDefenderTrojan.GenericKDZ.70716
BitDefenderThetaGen:NN.ZexaF.34570.uu0@aeFI62kO
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-9778048-0
AlibabaTrojan:Win32/EmotetCrypt.f4cf7e99
Ad-AwareTrojan.GenericKDZ.70716
SophosTroj/Emotet-CQM
InvinceaMal/Generic-R + Troj/Emotet-CQM
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.Emotet (A)
SentinelOneDFI – Malicious PE
JiangminTrojan.Banker.Emotet.oxa
eGambitUnsafe.AI_Score_82%
AviraTR/AD.Emotet.epa
MAXmalware (ai score=81)
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Emotet.R353241
Acronissuspicious
VBA32Trojan.Wacatac
ALYacTrojan.Agent.Emotet
TACHYONTrojan/W32.Agent.328192.TR
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HGTJ
TencentMalware.Win32.Gencirc.10ce0a4e
FortinetW32/BankerX.5CC7!tr
PandaTrj/Emotet.C
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM10.2.97DF.Malware.Gen

How to remove Win32/Kryptik.HGTJ?

Win32/Kryptik.HGTJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment