Malware

How to remove “Win32/Kryptik.HKRF”?

Malware Removal

The Win32/Kryptik.HKRF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKRF virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:14656
  • Unconventionial language used in binary resources: Vietnamese
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.HKRF?


File Info:

crc32: 7BC44840
md5: de416cad903def1a9ddccd49090bd598
name: DE416CAD903DEF1A9DDCCD49090BD598.mlw
sha1: fc7569c567463c19c23f1bba212a463ecaac6f31
sha256: 0987b4fdf6f7a39a16dd77c0313283a90d8e9aab97a69894c250606c99a53b82
sha512: 57731bccccf3a36ed54d0ff5522d3cdfe4f2b6b7c3e8df986322a70fcc137ccfe6f0038e3edc66b8f09020338c82b98ea76bc85ab01ad551747bdb97f93d3a4f
ssdeep: 98304:iIghk2tHxapa/CgW89yGFaUg4h5IYqAKnnaBnrZv7vR35htyv6XaK8pVrfKKDCL:Vgh1x8S/W89yGFaDYIY7KnUZv7J/tyC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.9.37.29
FileVerus: 1.0.52.18
Translations: 0x0286 0x01ea

Win32/Kryptik.HKRF also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46219286
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/GenKryptik.429c6359
K7GWTrojan ( 0057bc0f1 )
Cybereasonmalicious.567463
CyrenW32/Kryptik.DZC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKRF
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Malware.Generic-9857167-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.46219286
ViRobotTrojan.Win32.Z.Agent.6213120
MicroWorld-eScanTrojan.GenericKD.46219286
Ad-AwareTrojan.GenericKD.46219286
SophosML/PE-A + Mal/GandCrypt-A
BitDefenderThetaGen:NN.ZexaF.34686.@BW@ai2DqqjO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.de416cad903def1a
EmsisoftTrojan.GenericKD.46219286 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen3
MicrosoftRansom:Win32/LockBit!ml
AegisLabTrojan.Multi.Generic.4!c
GDataWin32.Trojan.Agent.53AXQY
AhnLab-V3Trojan/Win.MalPe.R418570
McAfeeArtemis!DE416CAD903D
MAXmalware (ai score=83)
VBA32BScope.Trojan.Razy
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002C0RE121
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
IkarusTrojan-Spy.Agent
FortinetW32/Kryptik.HKQX!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HKRF?

Win32/Kryptik.HKRF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment