Malware

How to remove “Win32/Kryptik.HHGY”?

Malware Removal

The Win32/Kryptik.HHGY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHGY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HHGY?


File Info:

crc32: B6CACD08
md5: 71db20fe3aef4b80f5b53a7f2c6d363e
name: IMG-2345678987687654367876543456.exe
sha1: 6f84c3f785b9c1840d8f0de0ce3e5b7918f5b740
sha256: 8524c16356ec2511b2623d04902d772836d3460de10f2dca77a8930a92703eae
sha512: e6279465d9e84e0d0ff01e2aa8303095df3f90b6792ddee2866fb0d18e83e0151db330a3caf8a928227ad845e2d08de374ef68e23d8e6016fb6bbf2ab5c836aa
ssdeep: 6144:95rg0igSmS/I29SuE7vJkrd2qr2hxB9j0/KyjSNCft4MdU4hg:k0igF291E7ux0xjyS4rGd
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HHGY also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35099083
FireEyeGeneric.mg.71db20fe3aef4b80
McAfeeRDN/GenericM
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005727c71 )
BitDefenderTrojan.GenericKD.35099083
K7GWTrojan ( 005727c71 )
Cybereasonmalicious.785b9c
TrendMicroTrojan.Win32.WACATAC.THKOFBO
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.Win32.Stelega.gen
AlibabaTrojan:Win32/Kryptik.847357da
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Outbreak.432128
AegisLabTrojan.Win32.Malicious.4!c
RisingMalware.Undefined!8.C (TFE:5:XDAVXjevhjD)
Ad-AwareTrojan.GenericKD.35099083
EmsisoftTrojan.GenericKD.35099083 (B)
DrWebTrojan.Inject4.4305
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Emotet.gc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.104286445.susgen
MicrosoftTrojan:Win32/Woreflint.A!cl
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D21791CB
ZoneAlarmHEUR:Trojan-PSW.Win32.Stelega.gen
GDataTrojan.GenericKD.35099083
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34590.AqZ@a8OLR2ni
ALYacTrojan.GenericKD.35099083
MalwarebytesTrojan.Injector
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HHGY
TrendMicro-HouseCallTrojan.Win32.WACATAC.THKOFBO
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.EVUS!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HHGY?

Win32/Kryptik.HHGY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment