Malware

Win32/Kryptik.HJBW information

Malware Removal

The Win32/Kryptik.HJBW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HJBW virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
apps.identrust.com
mynameisalfred.top

How to determine Win32/Kryptik.HJBW?


File Info:

crc32: DF3EAC53
md5: 0ff1ea0950acf744d7473174fa0edc13
name: 0FF1EA0950ACF744D7473174FA0EDC13.mlw
sha1: 0d47b8d12c66661007e8d124ac6374b60daad7f7
sha256: 00d0ab9311f0e39b740ec352c80eee3275df3c024ce77210405f11a28e19f543
sha512: 464b273756b7670fb6af3d0523c969e9fd20cb3f3eaefd8a9397c6b9a01d0381383bda06621d0b2d6886329b6c6fa1346d1372759c6523678c76580b6c264520
ssdeep: 6144:kDaHEy6dPO1LnQxL21DXH6HbHMCwsnZ4LJwrfgo3Nz1CVBJ1g2DcE0/e7AP9var:7Ey6dgDQxKDXaHT+9wvjCX/xz0/pP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HJBW also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36255297
FireEyeGeneric.mg.0ff1ea0950acf744
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.36255297
Cybereasonmalicious.12c666
CyrenW32/Kryptik.DCH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Exploit.Win32.Shellcode.gen
RisingTrojan.Generic@ML.86 (RDML:3D58fpYEHqhpjpyfTS6WmQ)
Ad-AwareTrojan.GenericKD.36255297
McAfee-GW-EditionBehavesLike.Win32.PUPXAA.hc
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmHEUR:Exploit.Win32.Shellcode.gen
GDataTrojan.GenericKD.36255297
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!0FF1EA0950AC
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
ESET-NOD32a variant of Win32/Kryptik.HJBW
FortinetW32/GenKryptik.FAQC!tr
BitDefenderThetaGen:NN.ZexaF.34780.GqW@aWYB24hO
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM10.1.E4E7.Malware.Gen

How to remove Win32/Kryptik.HJBW?

Win32/Kryptik.HJBW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment