Malware

What is “Win32/Kryptik.HJBE”?

Malware Removal

The Win32/Kryptik.HJBE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HJBE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/Kryptik.HJBE?


File Info:

name: 7F6070B7908DB5A6CB64.mlw
path: /opt/CAPEv2/storage/binaries/13f030724efec0cb7b91a6e5a6924b17fa77f6b4c47c32c773e96f86da21bfce
crc32: F0878DB4
md5: 7f6070b7908db5a6cb642617c4a6ea89
sha1: bae0cc4dc25fa971fed81aef1cc28faeb93eb9b2
sha256: 13f030724efec0cb7b91a6e5a6924b17fa77f6b4c47c32c773e96f86da21bfce
sha512: 7fea439a5a98b7ac47643699ef290413b65647868c8253947df814089132d8666ac24ad7bd69ff6c37e512e8852056eff77a07b76e88e4fea4545d3bea177e21
ssdeep: 3072:+K3kVWSLjgA0PQsr1McoJimd9JOmSI57eeHN2CCon5QLEyjQJ3yQUT:+K3kwSLjlsrmc3/leHNH248
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED346A2136F1C432F2B3A9798971C7F45E7BB8736935968E6AC006790F256D2DE2130B
sha3_384: 0e8036c31ab7cb287f8689854d6a657d293d5f087393c441944dc8b875a96d90280703d831b76a06e43aecb3de4c9b79
ep_bytes: e837560000e979feffffcccccccccccc
timestamp: 2019-08-04 20:30:16

Version Info:

FileVersion: 67.0.0.55
ProductVersion: 67.0.0.55
InternalName: cananilimodumator.exe
LegalCopyright: Wse
Translation: 0x0409 0x04e4

Win32/Kryptik.HJBE also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Mint.Titirez.oq0@oORqSUic
ClamAVWin.Packed.Jaik-9827128-0
FireEyeGeneric.mg.7f6070b7908db5a6
CAT-QuickHealRansom.Stop.P5
ALYacGen:Heur.Mint.Titirez.oq0@oORqSUic
MalwarebytesTrojan.MalPack.GS
VIPREGen:Heur.Mint.Titirez.oq0@oORqSUic
K7AntiVirusTrojan ( 00576dd01 )
AlibabaBackdoor:Win32/Tofsee.b8f40107
K7GWTrojan ( 00576dd01 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.DCU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HJBE
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
BitDefenderGen:Heur.Mint.Titirez.oq0@oORqSUic
NANO-AntivirusTrojan.Win32.Racealer.iiqdno
TencentWin32.Trojan-qqpass.Qqrob.Akpc
Ad-AwareGen:Heur.Mint.Titirez.oq0@oORqSUic
SophosMal/Generic-R + Troj/Kryptik-RL
F-SecureHeuristic.HEUR/AGEN.1224038
ZillyaTrojan.Kryptik.Win32.2849792
Trapminemalicious.high.ml.score
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1224038
GDataGen:Heur.Mint.Titirez.oq0@oORqSUic
GoogleDetected
AhnLab-V3Backdoor/Win32.Tofsee.R364479
BitDefenderThetaGen:NN.ZexaF.34592.oq0@aORqSUic
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
RisingTrojan.Kryptik!1.AD2D (CLASSIC)
YandexTrojan.Kryptik!xAI5/j8oBgM
MaxSecureRansomeware.CRAB.gen
FortinetPossibleThreat.PALLAS.H
Cybereasonmalicious.7908db
PandaTrj/GdSda.A

How to remove Win32/Kryptik.HJBE?

Win32/Kryptik.HJBE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment