Malware

Win32/Kryptik.HKST removal instruction

Malware Removal

The Win32/Kryptik.HKST is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKST virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

How to determine Win32/Kryptik.HKST?


File Info:

crc32: A3B631BF
md5: 305b76c9058ce1411415b11290b17a29
name: 305B76C9058CE1411415B11290B17A29.mlw
sha1: 5d5aab635267c583248e965a6b558cedca5c7ebc
sha256: 4d3c7ce0177fd26419433eafb989f6203ccf9726fd8b384940da0cf47b1c2803
sha512: 3fa838f0fc597a4c1638ce30adf680fa614039b94da977f87fa7501f78566518591cc8bd21901285b59d0d6d2086defd16e7e68e084c1ffc3ac638368ec22358
ssdeep: 24576:q6HlIV8DIFaG9nbkivQTLMJGRiOJvJXAoy0cjGQLcez52UZjXlm41Cs5pt6:q6HvHLMwfBoxLHz0wXlb1Cy6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709(C) 2021
InternalName: 8170
FileVersion: 1, 0, 0, 1
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft Corporation 8170
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: 8170
OriginalFilename: 8170.cmd
Translation: 0x0804 0x04b0

Win32/Kryptik.HKST also known as:

BkavW32.AIDetect.malware2
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37061561
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Kryptik.be6257b8
K7GWTrojan ( 0057c2661 )
Cybereasonmalicious.35267c
CyrenW32/Trojan.NXVW-0336
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKST
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
BitDefenderTrojan.GenericKD.37061561
MicroWorld-eScanTrojan.GenericKD.37061561
Ad-AwareTrojan.GenericKD.37061561
BitDefenderThetaGen:NN.ZexaF.34722.Er0@aOgOwXfb
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.305b76c9058ce141
EmsisoftTrojan.GenericKD.37061561 (B)
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D23583B9
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKD.37061561
McAfeeGenericRXOV-IK!305B76C9058C
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Lotok
MalwarebytesMalware.AI.4010216043
MaxSecureTrojan.Malware.300983.susgen
FortinetMalicious_Behavior.SB
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HKST?

Win32/Kryptik.HKST removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment