Malware

Win32/Kryptik.HHTT malicious file

Malware Removal

The Win32/Kryptik.HHTT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHTT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

How to determine Win32/Kryptik.HHTT?


File Info:

crc32: E4E233B2
md5: 80541165da69b3e291f6f425197ec101
name: 80541165DA69B3E291F6F425197EC101.mlw
sha1: 2b359a79448177613a7831f87030ae3289876ca2
sha256: d49cadf2065a50823d52ee585591da0d4a08c8d5d37f7d32c5f9d10fa9180c19
sha512: 04e1b6bff22c8b6904cdb4bd374a1f3d29b0a959751978a5c307ae190fc5662f22761103c8009d29a25516efa70fd3ae21c551a4796415d528e32a124d51252b
ssdeep: 3072:78qk4FRozXKEI7jQC5VrmpL2zqpOAZpDpOKfbG/lURhiOPdIYtuho3+B:78qkyT7jzGl22pJZJeSFA
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: DXPServer
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Device Stage Platform Server
OriginalFilename: DXPServer.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HHTT also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71549
FireEyeGeneric.mg.80541165da69b3e2
McAfeeArtemis!80541165DA69
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.71549
K7GWRiskware ( 0040eff71 )
CyrenW32/Kryptik.CNU.gen!Eldorado
APEXMalicious
RisingTrojan.MalCert!1.CF6C (CLASSIC)
Ad-AwareTrojan.GenericKDZ.71549
SophosMal/EncPk-APV
DrWebBackDoor.Qbot.551
TrendMicroTROJ_GEN.R06CC0RKQ20
McAfee-GW-EditionArtemis!Trojan
EmsisoftMalCert.A (A)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftTrojan:Win32/Qbot.MR!MTB
GridinsoftTrojan.Win32.Kryptik.oa!s3
ArcabitTrojan.Generic.D1177D
GDataTrojan.GenericKDZ.71549
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R356666
ALYacTrojan.GenericKDZ.71549
MAXmalware (ai score=85)
PandaTrj/Agent.AJS
ESET-NOD32a variant of Win32/Kryptik.HHTT
TrendMicro-HouseCallTROJ_GEN.R06CC0RKQ20
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HDNN!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove Win32/Kryptik.HHTT?

Win32/Kryptik.HHTT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment