Malware

About “Win32/Kryptik.HGXA” infection

Malware Removal

The Win32/Kryptik.HGXA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGXA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
puffpuff421.top
ocsp.digicert.com

How to determine Win32/Kryptik.HGXA?


File Info:

crc32: D3645F0D
md5: fa15ef9a1c8f164a9921c2097c8b79c6
name: FA15EF9A1C8F164A9921C2097C8B79C6.mlw
sha1: 6550e6401b5fc68e7a82e167811368902accf993
sha256: 0f3a62b00591669252ec0442ec1cb08c4d48f24d91c0012c8f685226dca5fc50
sha512: a8744b09786f4c3fc60113630a15c592be6358c45cda5a6b229b4629d21b9077670a60bf12091835e1826628f99390c7e003c2795fe55f77e326b0ec79ffc537
ssdeep: 12288:hQgQyOUb2uZaPg4ytvxB9x9lI/NWg3BmczF:qgQjUyuZaPCRvSlBmc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sracjoobz.exe
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, humke
TranslationUsi: 0x0032 0x0ccd

Win32/Kryptik.HGXA also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.59478
MicroWorld-eScanTrojan.GenericKDZ.70851
FireEyeGeneric.mg.fa15ef9a1c8f164a
McAfeeTrojan-FSWW!FA15EF9A1C8F
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056fc4c1 )
BitDefenderTrojan.GenericKDZ.70851
K7GWTrojan ( 0056fc4c1 )
Cybereasonmalicious.01b5fc
CyrenW32/Kryptik.CGA.gen!Eldorado
SymantecPacked.Generic.525
APEXMalicious
ClamAVWin.Dropper.Bunitu-9781268-0
Ad-AwareTrojan.GenericKDZ.70851
F-SecureHeuristic.HEUR/AGEN.1139051
InvinceaML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftTrojan.GenericKDZ.70851 (B)
AviraHEUR/AGEN.1139051
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Generic.D114C3
GDataTrojan.GenericKDZ.70851
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R353619
Acronissuspicious
VBA32BScope.Trojan.CryptInject
ALYacTrojan.GenericKDZ.70851
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Kryptik.HGXA
RisingTrojan.Kryptik!8.8 (TFE:4:fVZKmic53tD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HGXJ!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.352F.Malware.Gen

How to remove Win32/Kryptik.HGXA?

Win32/Kryptik.HGXA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment