Malware

Win32/Kryptik.HHWB removal tips

Malware Removal

The Win32/Kryptik.HHWB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHWB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HHWB?


File Info:

name: 013CD72FBBBBC1254C33.mlw
path: /opt/CAPEv2/storage/binaries/f0d1ac8c8713c6955c620a1dc6d6dbf303414c9dc9788767950de9be5608be14
crc32: BBCD5286
md5: 013cd72fbbbbc1254c3309f0a22350ac
sha1: 70763960ae0ec8c2f60f68558851381a1144f2aa
sha256: f0d1ac8c8713c6955c620a1dc6d6dbf303414c9dc9788767950de9be5608be14
sha512: b2267b57820601ad3bb34dc63ba206fceb9ed6d5e59c195ddf63b4bf16d8ff1246db57003094d6129320a921ad632fa435a48ad918657ca7535ee5340a0ace19
ssdeep: 3072:GpwVqrVYcK7R5bxq+QqvALVBZUBjRdDLPTbEJBAIJzGciszMe2oQYxeVHkeuQyZY:GpwcC7R1xq+QvLVBWBjRd3PEJiPOzX2t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D14F81AF521E01DC4D141F67ED8D6A86A10FBF4E46824737FC23B0159A40EA9DE2FA7
sha3_384: 04fc419682ab6c6909b7f4da82cc30dc8549000f98183e08838a6bf695ddba5a809e38bfac60968655c4ab09142ef77a
ep_bytes: e9872a0000e9b3fdffff8bff558bec8b
timestamp: 2016-04-01 08:09:12

Version Info:

0: [No Data]

Win32/Kryptik.HHWB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.740561
FireEyeGeneric.mg.013cd72fbbbbc125
McAfeeGenericRXNJ-MG!013CD72FBBBB
CylanceUnsafe
Cybereasonmalicious.fbbbbc
CyrenW32/Kryptik.DED.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHWB
APEXMalicious
KasperskyBackdoor.Win32.Mokes.aoad
BitDefenderGen:Variant.Razy.740561
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Razy.740561
EmsisoftGen:Variant.Razy.740561 (B)
McAfee-GW-EditionGenericRXNJ-MG!013CD72FBBBB
SophosMal/Generic-S
GDataGen:Variant.Razy.740561
eGambitUnsafe.AI_Score_64%
AviraHEUR/AGEN.1121409
ArcabitTrojan.Razy.DB4CD1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R374742
BitDefenderThetaGen:NN.ZexaF.34084.lu0@aaNt8bci
ALYacGen:Variant.Razy.740561
MAXmalware (ai score=89)
VBA32BScope.Trojan-Spy.Win32.Zbot
MalwarebytesTrojan.SmokeLoader
RisingTrojan.Generic@ML.92 (RDML:laoXFmUU0mp39Qk2JLkKag)
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.ACGU!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Win32/Kryptik.HHWB?

Win32/Kryptik.HHWB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment