Malware

Win32/Kryptik.HKSU removal guide

Malware Removal

The Win32/Kryptik.HKSU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKSU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Unconventionial language used in binary resources: Malay (Brunei Darussalam)
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua
jfus.top

How to determine Win32/Kryptik.HKSU?


File Info:

crc32: 3CCFDDAD
md5: 3273348793ce07669029002d75dd8537
name: 3273348793CE07669029002D75DD8537.mlw
sha1: 569b75917dba0c6e8c3b45cae6f66e1258316b57
sha256: 2fb3d980507741c8bbe5ddaa3ccee423d774bb9ec2f1c21c74b2eef05a5c62c1
sha512: c7cc20fef710d595dbe7d07e0cbbd78da2a44695ca26f84079e20cecdc03ae10ce10dcdfe5d8c9547e6ef3e417bf7fa62e20410057069201f372f81071de85f1
ssdeep: 24576:nRguPthdB32a+di3WqdaTbftfm6Wy+RBE:qCuBY/a/fI69kBE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.9.37.29
FileVersion: 1.0.52.18
Translations: 0x0386 0x010e

Win32/Kryptik.HKSU also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop16.48384
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Application/Obfuscated.b7e46be6
Cybereasonmalicious.17dba0
CyrenW32/Kryptik.EAC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKSU
APEXMalicious
AvastFileRepMalware
KasperskyUDS:DangerousObject.Multi.Generic
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34688.Zq0@auc4uClO
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.3273348793ce0766
eGambitUnsafe.AI_Score_86%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
AegisLabTrojan.Multi.GenericML.4!c
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan-Ransom.STOP.3KU7HX
Acronissuspicious
McAfeeArtemis!3273348793CE
VBA32BScope.Backdoor.Convagent
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
RisingMalware.Undefined!8.C (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.HKSU?

Win32/Kryptik.HKSU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment