Malware

How to remove “Win32/Kryptik.HKZF”?

Malware Removal

The Win32/Kryptik.HKZF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKZF virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in

How to determine Win32/Kryptik.HKZF?


File Info:

crc32: 4DC76A3B
md5: 3b85aca7e056450b11adc53e7e14c9b9
name: 3B85ACA7E056450B11ADC53E7E14C9B9.mlw
sha1: 0acd1ebc3a3008f037d5eceb73f8531bd949da73
sha256: b8c27a80517c30d881adb152ce2f93f3be1d2446028bf2b5bdbecb8ac766633f
sha512: d4d999af10539cf33684f329a3e839b59e31ed5bb8d1001f4dc1959ff896a53a16feafdd175c0f6ee5a50f897eefa312ca5ede78cd4f42a29579e0369e88e172
ssdeep: 12288:OMVb1/VlkSJnLAh3D7Fxh8Tcnt4zDyw7AXJZWfqkShqHAXsLj:OK/VFcD7yTcnS7A5aqkWhXsLj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersus: 1.0.95.18
ProductVersus: 1.0.87.28
Translations: 0x0185 0x00fa

Win32/Kryptik.HKZF also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.DanaBot.371
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.c3a300
CyrenW32/Kryptik.EDK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKZF
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Pwsx-9863541-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKDZ.75354
MicroWorld-eScanTrojan.GenericKDZ.75354
Ad-AwareTrojan.GenericKDZ.75354
SophosML/PE-A + Mal/GandCrypt-B
BitDefenderThetaGen:NN.ZexaF.34690.LuW@aKMMGFpO
McAfee-GW-EditionBehavesLike.Win32.Lockbit.hc
FireEyeGeneric.mg.3b85aca7e056450b
EmsisoftTrojan.GenericKDZ.75354 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Azorult.RTH!MTB
GridinsoftTrojan.Heur!.02014021
ArcabitTrojan.Graftor.DE8E9E
ZoneAlarmHEUR:Trojan-Ransom.Win32.Stop.gen
GDataWin32.Trojan.PSE.14FJAB1
AhnLab-V3Trojan/Win.Glupteba.R421764
Acronissuspicious
McAfeeArtemis!3B85ACA7E056
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazqqq8wa9b0KWFdvsI1S68R0)
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HKZH!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HKZF?

Win32/Kryptik.HKZF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment