Malware

How to remove “Win32/Kryptik.HGZJ”?

Malware Removal

The Win32/Kryptik.HGZJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGZJ virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HGZJ?


File Info:

crc32: 7D3B59F4
md5: 3c6a408f9ed7b3c9779cb15c7cbf89cb
name: 3C6A408F9ED7B3C9779CB15C7CBF89CB.mlw
sha1: 9b4fcf073d5b977d5bae181f5e66bd52f4ab10f5
sha256: 9d23c44c4d08bb4ac7c6d3174e4484f17cd8e786b010ddf246fcb341f185f69c
sha512: 138c25cc3582984510da8e1e521909a1e8c4c63d0aeba34abd0269ed003604e4e869053d142e371bed88a7b89962a0ddf8e4f8e01375bd84dccfde44549a4fe7
ssdeep: 12288:46xUH6xUH6xUakyC/82TQh9mgdVHh1HxgS42OTOuH:4XHXHXaY9To9mgdT1HM2OTOY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2009-2014 Safer-Networking Ltd. All rights reserved.
FileVersion: 2.4.40.151
CompanyName: Safer-Networking Ltd.
LegalTrademarks: Spybotxae and Spybot - Search & Destroyxae are registered trademarks.
ProductName: Spybot - Search & Destroy
ProductVersion: 2.4.40.0
FileDescription: Dummy
OriginalFilename: blindman.exe
Build: 20140425
Translation: 0x1809 0x04e4

Win32/Kryptik.HGZJ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.773109
FireEyeGeneric.mg.3c6a408f9ed7b3c9
Qihoo-360HEUR/QVM19.1.455B.Malware.Gen
ALYacGen:Variant.Razy.773109
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Razy.773109
K7GWRiskware ( 0049f6ae1 )
K7AntiVirusRiskware ( 0049f6ae1 )
SymantecML.Attribute.HighConfidence
AvastWin32:DangerousSig [Trj]
ClamAVWin.Packed.Razy-9790905-0
KasperskyHEUR:Trojan-Downloader.Win32.Cridex.vho
TencentMalware.Win32.Gencirc.11b10f53
Ad-AwareGen:Variant.Razy.773109
SophosTroj/Agent-AJFK
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Dridex.735
InvinceaTroj/Agent-AJFK
McAfee-GW-EditionGenericRXMK-ZC!3C6A408F9ED7
EmsisoftGen:Variant.Razy.773109 (B)
JiangminTrojanDownloader.Cridex.zd
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.D9!ml
GridinsoftTrojan.Heur!.00012031
ArcabitTrojan.Razy.DBCBF5
ZoneAlarmHEUR:Trojan-Downloader.Win32.Cridex.vho
GDataGen:Variant.Razy.773109
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R354166
McAfeeGenericRXMK-ZC!3C6A408F9ED7
MAXmalware (ai score=88)
VBA32BScope.TrojanDownloader.Cridex
MalwarebytesTrojan.MalPack.DGI.Generic
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HGZJ
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Kryptik.HHFV!tr
BitDefenderThetaGen:NN.ZexaF.34634.QW1@auUA0gbi
AVGWin32:DangerousSig [Trj]
Cybereasonmalicious.73d5b9

How to remove Win32/Kryptik.HGZJ?

Win32/Kryptik.HGZJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment