Malware

Win32/Kryptik.HHRT removal

Malware Removal

The Win32/Kryptik.HHRT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHRT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (9 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

www.bing.com
ocsp.digicert.com
mem.gfx.ms
img-prod-cms-rt-microsoft-com.akamaized.net
publisher.liveperson.net

How to determine Win32/Kryptik.HHRT?


File Info:

crc32: D02BDC03
md5: 75dd85a6d1389e53fb125ebd9d2711a3
name: 75DD85A6D1389E53FB125EBD9D2711A3.mlw
sha1: 39d33f5c7aa2364f0f345f566946758ad3af80d4
sha256: 2b120acc21bb146f94d229b7efeef732ab31dc9874fa00174f61e7673982a309
sha512: 1a0ac909fa0ad554dc2972679c5f8a0bc944d435595eb9de227ff2f6fa70cffdfd05857df1cec16d11589550f80d3f004c6d471e9a291b50ff0e466e66493116
ssdeep: 3072:Y4cYSAmimVnYVVfoaxG2JgvlsJU/GLDUdx6SkIQWW:npWVVneVgcGGgsJHYrP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVer: 2.0.9.29
FileV: 1.0.2.37
Translations: 0x0255 0x029d

Win32/Kryptik.HHRT also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44637833
FireEyeGeneric.mg.75dd85a6d1389e53
Qihoo-360HEUR/QVM10.1.8827.Malware.Gen
ALYacTrojan.GenericKD.44637833
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.44637833
K7GWHacktool ( 700007861 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34658.lqW@aGZrhLiO
CyrenW32/Glupteba.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Glupteba-9800473-0
KasperskyHEUR:Backdoor.Win32.Androm.gen
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
Ad-AwareTrojan.GenericKD.44637833
SophosML/PE-A
F-SecureTrojan.TR/Crypt.Agent.pdzdy
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
EmsisoftTrojan.Crypt (A)
IkarusTrojan.Win32.Ranumbot
AviraTR/Crypt.Agent.pdzdy
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Ranumbot.RQ!MSR
ArcabitTrojan.Generic.D2A91E89
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Backdoor.Win32.Androm.gen
GDataWin32.Trojan.PSE.E1MOMX
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.C4230338
Acronissuspicious
McAfeeTrojan-FSUC!75DD85A6D138
VBA32BScope.Trojan.DelShad
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HHRT
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_79%
FortinetW32/Kryptik.HHRC!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c7aa23
AvastWin32:TrojanX-gen [Trj]

How to remove Win32/Kryptik.HHRT?

Win32/Kryptik.HHRT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment