Malware

Win32/Kryptik.HGVI removal tips

Malware Removal

The Win32/Kryptik.HGVI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGVI virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HGVI?


File Info:

crc32: 1E7BBD67
md5: b226ebaf60b89c1d2b08a7e983547f81
name: B226EBAF60B89C1D2B08A7E983547F81.mlw
sha1: df935b43fe03b0e600c7b941c117407088b19637
sha256: 88b7052774af9a119ee74920eb5e658bdb0abcf7515101557a42cfc5eb8a9344
sha512: 2d8faefd009defacde0ccc99b13ad1ea23db94eca44aa78ba764dd8a1c1201faf8574f95536f9f51616a39e51e18fd765896f176ca9592a976872d65e3172db5
ssdeep: 6144:KYn7j1CCC3YgFczfgfc6QsXVTG7iKuOg888888888888W88888888888r:B7j1CCC3YgeicCVTGqOg88888888888i
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxa9 2015 IObit. All Rights Reserved.
InternalName: AYPDATE
FileVersion: 3.3.2.133
CompanyName: IObit
LegalTrademarks: IObit
FileDescription: IObit AYPDATE

Win32/Kryptik.HGVI also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.5189
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.G4
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1306529
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.d84dbf54
K7GWTrojan ( 005224381 )
Cybereasonmalicious.f60b89
BaiduWin32.Trojan.Kryptik.anp
CyrenW32/Locky.H2.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.HGVI
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Packed.Win32.Mentiger.gen
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Mentiger.evdbcf
SUPERAntiSpywareRansom.Cerber/Variant
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentMalware.Win32.Gencirc.10b5875f
Ad-AwareTrojan.Ransom.Cerber.1
SophosML/PE-A + Mal/Ransom-EJ
ComodoTrojWare.Win32.Kryptik.ERJ@6l0vie
BitDefenderThetaGen:NN.ZexaF.34608.uq1@aWWsKUlj
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SM2
McAfee-GW-EditionBehavesLike.Win32.Ransomware.fh
FireEyeGeneric.mg.b226ebaf60b89c1d
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1124969
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Cerber.A
ArcabitTrojan.Ransom.Cerber.1
AegisLabHacktool.Win32.Generic.x!c
ZoneAlarmHEUR:Packed.Win32.Mentiger.gen
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-GCQ!B226EBAF60B8
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Cerber
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCERBER.SM2
RisingTrojan.Kryptik!1.AF0E (CLOUD)
YandexTrojan.GenAsa!VYaJBsMFFg8
IkarusTrojan.Ransom.Cerber
FortinetW32/Kryptik.HCAW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBbLsA

How to remove Win32/Kryptik.HGVI?

Win32/Kryptik.HGVI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment