Malware

Win32/Kryptik.HHFD removal guide

Malware Removal

The Win32/Kryptik.HHFD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHFD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HHFD?


File Info:

crc32: 5FEBC79B
md5: d981daa9ff70ed4636b60b1f9b7d42e5
name: D981DAA9FF70ED4636B60B1F9B7D42E5.mlw
sha1: 231b4479f3cf1aa97e5094f1bc8700c2f53a0aef
sha256: 4373b230b018aaf9f458fd0d90b29fa03cfba0322c70a793ac4239d36fabd3c5
sha512: cc1c00bc82ca42370f0030abeddd51b0405e78930c9bb95e7a35db576fc06249acc3b85f9b8e986e95982e36c8e831aa6c771767ee4a376a6321def64c08c191
ssdeep: 6144:fcxLjeIL1/lI9ePfOysxLVbaQq/FCiz44eAxA8OFE+vYW5999NM/FS:fWeIB/lLG3NMNS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0

Win32/Kryptik.HHFD also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.350263
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.9ff70e
CyrenW32/MSIL_Kryptik.CZX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHFD
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Mokes.anqw
BitDefenderGen:Variant.Zusy.350263
MicroWorld-eScanGen:Variant.Zusy.350263
Ad-AwareGen:Variant.Zusy.350263
BitDefenderThetaGen:NN.ZexaF.34266.ou0@aqNqFxgi
McAfee-GW-EditionBehavesLike.Win32.BadFile.dh
FireEyeGeneric.mg.d981daa9ff70ed46
EmsisoftGen:Variant.Zusy.350263 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Generic.ASMalwS.31069FC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.350263
AhnLab-V3Malware/Win32.Generic.C4222258
McAfeeArtemis!D981DAA9FF70
MAXmalware (ai score=81)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.SmokeLoader
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D2DE (CLASSIC)
FortinetW32/Agent.ACGU!tr
AVGWin32:Trojan-gen

How to remove Win32/Kryptik.HHFD?

Win32/Kryptik.HHFD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment