Malware

What is “Win32/Kryptik.HJEY”?

Malware Removal

The Win32/Kryptik.HJEY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HJEY virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications

How to determine Win32/Kryptik.HJEY?


File Info:

crc32: 9A9EA541
md5: a21a285ce9482d0a0a45f4f33063c608
name: A21A285CE9482D0A0A45F4F33063C608.mlw
sha1: 8d519eb98ddda64f7733a3251d1d14d13dde54eb
sha256: 47ce31756f024d900bc4dbfb7c7c3c5ff6ef1ae93e99a7ec1e2467253297cefb
sha512: f86fd14087d9d65a94082f025f48ea75ad8595487b7265a1ac9b3e43eeffae0a21015fcc682d4c5693aec8f7e6f5653f3802f98daf6406174cfe747ec6cabaff
ssdeep: 6144:CK6cyPiWCgknQ/HuyIzuTVzsMM56519p+6yTDy1GeS3KmJBC0+eekTdFyDPckaS:CM+ZdkmHubeaCo6r1GeSTjvODPL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Tonec Inc., Copyright xa9 1999 - 2015
InternalName: IDMGrHlp
FileVersion: 6, 22, 1, 1
CompanyName: Tonec Inc.
LegalTrademarks: Internet Download Manager
Comments: Auxiliary program for Internet Download Manager
ProductName: Internet Download Manager
ProductVersion: 6, 22, 1, 1
FileDescription: Internet Download Manager module
OriginalFilename: IDMGrHlp.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HJEY also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005796721 )
LionicTrojan.Win32.Cridex.a!c
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.735
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.928020
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005796721 )
CyrenW32/Kryptik.CEK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HJEY
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Downloader.Win32.Cridex.mqa
BitDefenderGen:Variant.Razy.928020
MicroWorld-eScanGen:Variant.Razy.928020
TencentWin32.Trojan-downloader.Cridex.Liqc
Ad-AwareGen:Variant.Razy.928020
SophosMal/Generic-S + Mal/EncPk-APV
BitDefenderThetaGen:NN.ZexaF.34142.4u0@aSI8Dodi
McAfee-GW-EditionBehavesLike.Win32.BadFile.ct
FireEyeGeneric.mg.a21a285ce9482d0a
EmsisoftGen:Variant.Razy.928020 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Dridex.xbebs
Antiy-AVLTrojan/Generic.ASMalwS.1650A5
MicrosoftTrojan:Script/Phonzy.C!ml
ArcabitTrojan.Razy.DE2914
GDataGen:Variant.Razy.928020
AhnLab-V3Trojan/Win.Generic.R441621
McAfeeGenericRXQB-DG!A21A285CE948
MAXmalware (ai score=86)
VBA32TrojanDownloader.Cridex
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0RII21
RisingTrojan.Kryptik!1.D606 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/EncPk.APV!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HJEY?

Win32/Kryptik.HJEY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment