Malware

Win32/Kryptik.HKVI malicious file

Malware Removal

The Win32/Kryptik.HKVI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKVI virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs

How to determine Win32/Kryptik.HKVI?


File Info:

crc32: E6A7814A
md5: bd4c97f08e1494d7131ac8899ea5b52d
name: BD4C97F08E1494D7131AC8899EA5B52D.mlw
sha1: 6db5826618466f8abdff7226289442d3220969a5
sha256: 385eb4274de2282360a7010b5739769fb6dd69a889626c0fddc6a3a6d4c1251f
sha512: 55090a595587de918e670ebec5c49b18280ad6fb873d3619c57f6454305c380194742c12eae05b8b9a101e598de77056626379693bcbf5ceb27b4bae4ae726a9
ssdeep: 49152:vKlCu2s0sKE72L2JyYIicvrNPNTnMXeikpejKouT:vKlZwsKE7a2JyYIdrNPNTMXeikgjKouT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2015-2021 Exodus Movement, Inc.
InternalName: Exodus
OriginalFileName:
FileVersion: 21.5.7
CompanyName: Exodus Movement Inc
SquirrelAwareVersion: 1
ProductName: Exodus
ProductVersion: 21.5.7
FileDescription: Exodus
OriginalFilename: Exodus.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.HKVI also known as:

DrWebBackDoor.Rat.354
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.36884949
AlibabaTrojan:Win32/Glupteba.950d61df
K7GWTrojan ( 0057c5941 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Kryptik.HKVI
AvastFileRepMetagen [Malware]
BitDefenderTrojan.GenericKD.36884949
MicroWorld-eScanTrojan.GenericKD.36884949
Ad-AwareTrojan.GenericKD.36884949
ComodoMalware@#lwglubj0lngb
VIPRETrojan.Win32.Generic!BT
FireEyeTrojan.GenericKD.36884949
EmsisoftMalCert.A (A)
WebrootW32.Trojan.Gen
AviraTR/AD.ParallaxRat.rwsil
MicrosoftTrojan:Win32/Glupteba.STA
GDataTrojan.GenericKD.36884949
AhnLab-V3Trojan/Win.Glupteba.C4469832
McAfeeArtemis!BD4C97F08E14
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack
RisingTrojan.Glupteba!8.AA0 (CLOUD)
FortinetW32/Kryptik.HKVI!tr
AVGFileRepMetagen [Malware]

How to remove Win32/Kryptik.HKVI?

Win32/Kryptik.HKVI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment