Malware

Win32/Kryptik.HHBJ removal guide

Malware Removal

The Win32/Kryptik.HHBJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHBJ virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • A process sent information about the computer to a remote location.
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.ipify.org
epperhaptem.com
blemecem.com

How to determine Win32/Kryptik.HHBJ?


File Info:

crc32: C978D5E4
md5: 28e9316fb298d2e7a3d9fd71c662b3ec
name: k.png
sha1: 1c3737add4444a2cb0842d1a5535005b7aa8e7a4
sha256: de5e9077481f7cf0b1addaeaaf21d6d39cabed2eea02276aaf9c241bce446c3d
sha512: ccf5bfd384e231180a8e1153b45a0be518d17dc782335d47c543f9dba48cd03c6bf7ce0b34dde92b88f404e248e7484dfac6c1f39dde5a40f40eafdf53eb7bce
ssdeep: 1536:Xjqyf5N4bPNAhwJ+Or+zfUS65zz4070+AaLRLsXznayUjS9a95FaDek1ioQ+g3:Xjqyf5NeqaJ+q+zfBGzzHgoLsXvB7u3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) Copyright 2016 StationPlaylist.com
InternalName:
FileVersion: 5.2.0.11
CompanyName: StationPlaylist.com
LegalTrademarks:
FileDescription: Track Tool
Translation: 0x1409 0x04e4

Win32/Kryptik.HHBJ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34974911
FireEyeGeneric.mg.28e9316fb298d2e7
McAfeeRDN/Generic.grp
CylanceUnsafe
AegisLabTrojan.Win32.Geral.a!c
SangforMalware
K7AntiVirusTrojan ( 00571f211 )
BitDefenderTrojan.GenericKD.34974911
K7GWTrojan ( 00571f211 )
CrowdStrikewin/malicious_confidence_80% (W)
InvinceaMal/Generic-S
SymantecPacked.Generic.459
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Geral.brdh
AlibabaTrojanDownloader:Win32/Geral.baaca978
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKD.34974911
SophosMal/Generic-S
ComodoMalware@#18y2kixm5r9pf
F-SecureTrojan.TR/AD.DInject.apiln
DrWebTrojan.Chanitor.59
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.WACATAC.USMANJS20
McAfee-GW-EditionRDN/Generic.grp
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Spy.Agent
WebrootW32.Trojan.Gen
AviraTR/AD.DInject.apiln
MAXmalware (ai score=95)
MicrosoftTrojan:Win32/Ymacco.AAC6
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.Generic.D215ACBF
ZoneAlarmTrojan-Downloader.Win32.Geral.brdh
GDataTrojan.GenericKD.34974911
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.PW1@a0hngZvi
ALYacTrojan.Agent.Hancitor
VBA32BScope.Trojan.Inject
MalwarebytesTrojan.MalPack.DGI.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HHBJ
TrendMicro-HouseCallTrojan.Win32.WACATAC.USMANJS20
TencentWin32.Trojan-downloader.Geral.Hugf
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.HHBJ!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.dd4444
AvastWin32:CrypterX-gen [Trj]
Qihoo-360Generic/HEUR/QVM20.1.E47F.Malware.Gen

How to remove Win32/Kryptik.HHBJ?

Win32/Kryptik.HHBJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment