Malware

Win32/Kryptik.HHKE malicious file

Malware Removal

The Win32/Kryptik.HHKE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHKE virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HHKE?


File Info:

crc32: FDEE6DCF
md5: 9d1e0d1fca97aef998fb435be680ecf1
name: 9D1E0D1FCA97AEF998FB435BE680ECF1.mlw
sha1: 542f12d33e139281e85782e2febafff2722d0916
sha256: 371dc3399511270ac4a84b08bc10d26e90f051bf1bd1e920650b28e097faaf91
sha512: 7b6e388d7eb1702d4fab8ba6e6e627fd54f9dbb121485009612095abeda971d331b37a910bd366a49ac05e419034e51ccdc975403a6ca3ab79e41daec831ce2f
ssdeep: 12288:fqPc291E7IkP8p3Yk+Ml5ikmUikXcV2b:iPcE1WIZp3Y/MOkmUvZ
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HHKE also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.4524
MicroWorld-eScanGen:Variant.Zusy.333872
CAT-QuickHealTrojanpws.Stelega
Qihoo-360HEUR/QVM20.1.44A7.Malware.Gen
ALYacGen:Variant.Zusy.333872
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005727211 )
BitDefenderGen:Variant.Zusy.333872
K7GWTrojan ( 005727211 )
BitDefenderThetaGen:NN.ZexaE.34634.yqZ@auILseci
CyrenW32/Kryptik.CKN.gen!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:CrypterX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
TencentMalware.Win32.Gencirc.10ce133e
Ad-AwareGen:Variant.Zusy.333872
EmsisoftGen:Variant.Zusy.333872 (B)
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.fc
FireEyeGeneric.mg.9d1e0d1fca97aef9
IkarusTrojan.Agent
MAXmalware (ai score=81)
MicrosoftTrojanSpy:Win32/Stelega.MR!MTB
ArcabitTrojan.Zusy.D51830
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Zusy.333872
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4222221
McAfeeGenericRXMN-CL!9D1E0D1FCA97
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HHKE
RisingTrojan.Kryptik!1.CE90 (CLASSIC)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HHKE?

Win32/Kryptik.HHKE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment