Malware

Should I remove “Win32/Kryptik.HHPZ”?

Malware Removal

The Win32/Kryptik.HHPZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHPZ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

iplogger.org

How to determine Win32/Kryptik.HHPZ?


File Info:

crc32: BB53B363
md5: bbd90fb73735909ca76da0063966966e
name: BBD90FB73735909CA76DA0063966966E.mlw
sha1: 28b222b9f8b8e3119ccda9ece133a1eb37d0201c
sha256: aa0bce1f6c467a14f58b4897f23c70c80bd690ea91cc6855bc3c060b5b903cf9
sha512: 6090a0ee07e0fb7958e0479f22c0c524848d1112ce61f21d7577e374246741de0d6335b5af8589a8bb4107ffb74b230883cb105e00e5724b54116e5b1f549f3d
ssdeep: 12288:yBUdt390L9JH3m/1si4iVlsrrJ15ruT4tpyEn/HqXkH77l:yByk9d3m/1UsYRuToMIikH77l
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: driseapoges.atb
FileVers: 15.26.361
Copyright: Copyrighz (C) 2020, pipkabop
TranslationUsa: 0x0471 0x0986

Win32/Kryptik.HHPZ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71498
FireEyeGeneric.mg.bbd90fb73735909c
Qihoo-360HEUR/QVM10.1.9097.Malware.Gen
ALYacTrojan.GenericKDZ.71498
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005738cb1 )
BitDefenderTrojan.GenericKDZ.71498
K7GWTrojan ( 005738cb1 )
Cybereasonmalicious.737359
CyrenW32/Kryptik.CLI2.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Zenpak.pef
Ad-AwareTrojan.GenericKDZ.71498
EmsisoftTrojan.GenericKDZ.71498 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Glupteba.RQ!MSR
ArcabitTrojan.Generic.D1174A
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
GDataTrojan.GenericKDZ.71498
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R356004
Acronissuspicious
McAfeePacked-GCZ!BBD90FB73735
MAXmalware (ai score=82)
VBA32BScope.Trojan.Azorult
MalwarebytesRansom.LockBit
ESET-NOD32a variant of Win32/Kryptik.HHPZ
RisingTrojan.Kryptik!1.CF5C (CLASSIC)
IkarusWin32.Outbreak
FortinetW32/Kryptik.HHPZ!tr
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HHPZ?

Win32/Kryptik.HHPZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment