Malware

Win32/Kryptik.HHRO removal guide

Malware Removal

The Win32/Kryptik.HHRO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHRO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
newcoldstart.com
a.tomx.xyz
ip-api.com

How to determine Win32/Kryptik.HHRO?


File Info:

crc32: 98122AA6
md5: 832de8a381364d993401df583ed8370c
name: 832DE8A381364D993401DF583ED8370C.mlw
sha1: c637b174a8597436d7daf54feb7b02e4bd995279
sha256: 53aa433c101f4bf08e503a323146bb67665931a9cf89915d238e80018dcc7d1e
sha512: 856661068fe3e9a9ca7b9e09fb888fa2fc375229e7c9eb8afd279abca67546ca012a39c7751a798fff771aefed0964badc729789fd0d8486d78663ec1f041fa1
ssdeep: 12288:l7spw2zzv7nh8HJpwsrpUoCZLFilRLGfwKMJRl7:lAzzv7h8HJyKpU30R
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVer: 2.0.9.29
FileV: 1.0.2.37
Translations: 0x0255 0x029d

Win32/Kryptik.HHRO also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71537
McAfeeTrojan-FSUC!832DE8A38136
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKDZ.71537
K7GWTrojan ( 0056f9be1 )
K7AntiVirusTrojan ( 0056f9be1 )
ArcabitTrojan.Generic.D11771
CyrenW32/Glupteba.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.71537
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.832de8a381364d99
EmsisoftTrojan.GenericKDZ.71537 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=81)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Ranumbot.RQ!MSR
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.PSE.E1MOMX
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4230244
Acronissuspicious
ALYacGen:Variant.Graftor.860214
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HHRO
IkarusWin32.Outbreak
eGambitUnsafe.AI_Score_88%
FortinetW32/Kryptik.HHRC!tr
BitDefenderThetaGen:NN.ZexaF.34658.EqW@aCQyfEmO
Qihoo-360HEUR/QVM10.1.815B.Malware.Gen

How to remove Win32/Kryptik.HHRO?

Win32/Kryptik.HHRO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment