Malware

About “Win32/Kryptik.HHAB” infection

Malware Removal

The Win32/Kryptik.HHAB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHAB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HHAB?


File Info:

crc32: EE3B4251
md5: ef555c31d6b5ae574af31e574d528466
name: m797508E2-20F2-42C-879A-1C358609BA01.exe
sha1: 4ea0455bbfd013b3892c64f5c459771df3500914
sha256: 651b6664d1612cd3c4ed1c01f42116afd74aeacd10148b3c489ba31d594731ca
sha512: 8035f3942909757d5b5965ef6d60d48aea01cfc37b54aba6cb8449f756e6818b4c5eac60b136f6d93a9c34327ea4ed14d7ded59fe2ed52df91ddb54e954ca780
ssdeep: 12288:S+fsQpn4A+OpKLr/WnsBAeKzJ7FUyCsrV6:x6D8ms56
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HHAB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44163677
FireEyeGeneric.mg.ef555c31d6b5ae57
CAT-QuickHealTrojan.Injects
McAfeeRDN/Generic.grp
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 00571d471 )
BitDefenderTrojan.GenericKD.44163677
K7GWTrojan ( 00571d471 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Injects.gen
AlibabaTrojan:Win32/Kryptik.affdb48c
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Obfuscator.594432
RisingTrojan.Generic@ML.89 (RDML:Ufhrdf5k3Ao2bcWJEYR44w)
Ad-AwareTrojan.GenericKD.44163677
DrWebTrojan.PWS.Stealer.29163
VIPREVirTool.Win32.Obfuscator.da!k (v)
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
AviraTR/PSW.Stealer.cucor
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/CryptInject!ml
ArcabitTrojan.Generic.D2A1E25D
ZoneAlarmHEUR:Trojan.Win32.Injects.gen
GDataTrojan.GenericKD.44163677
AhnLab-V3Malware/Win32.Generic.C4212985
BitDefenderThetaGen:NN.ZexaF.34590.KuZ@amqrsqii
ALYacTrojan.GenericKD.44163677
VBA32BScope.TrojanSpy.Noon
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HHAB
TencentWin32.Trojan.Injects.Amvt
SentinelOneDFI – Malicious PE
FortinetW32/Kryptik.GGTA!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove Win32/Kryptik.HHAB?

Win32/Kryptik.HHAB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment