Malware

About “Win32/Kryptik.HKGY” infection

Malware Removal

The Win32/Kryptik.HKGY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKGY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HKGY?


File Info:

crc32: 0C73F220
md5: 0b6e3a48c0c55996ebd0fb4c02ad34f3
name: 0B6E3A48C0C55996EBD0FB4C02AD34F3.mlw
sha1: 5d0ec73e21d32b89d3a8444ec4563a451ecedcd7
sha256: 063599342888ca8db39fbfa1a514614781beae26ef228c4c6a5a3f99b67b6a63
sha512: 4913eddbd9cd0ccfb04cc405a5fe3ab69c13b59ade346eddd58824261c7c7e627b7d51a8c7268386c212fb3ba07ee3893331f063a236a40b1484656c9765a061
ssdeep: 12288:XVLUpsUGuIvm6gQbbJu5SZ31dfTjCBtnFav/601:lysUqOKnAAZ31dOt4/601
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calimatimodunads.exe
FileVersions: 7.0.2.54
LegalCopyrights: Vsekda
ProductVersions: 7.0.21.45
Translation: 0x0129 0x0563

Win32/Kryptik.HKGY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36639242
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.eb4e491f
K7GWRiskware ( 0040eff71 )
CyrenW32/Kryptik.DTP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKGY
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Dropper.Tofsee-9850328-0
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.GenericKD.36639242
MicroWorld-eScanTrojan.GenericKD.36639242
Ad-AwareTrojan.GenericKD.36639242
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34670.Ku0@aOlB6wgG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.0b6e3a48c0c55996
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftPWS:Win32/Predator.GKM!MTB
ArcabitTrojan.Generic.D22F120A
AegisLabTrojan.Win32.Malicious.4!c
GDataWin32.Trojan-Stealer.Raccoon.LUTE6X
AhnLab-V3Trojan/Win.Predator.R414768
McAfeePacked-GBF!0B6E3A48C0C5
MAXmalware (ai score=80)
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D4B0 (CLOUD)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HKHB!tr
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCYjsA

How to remove Win32/Kryptik.HKGY?

Win32/Kryptik.HKGY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment