Malware

Win32/Kryptik.HNFH removal

Malware Removal

The Win32/Kryptik.HNFH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNFH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
mas.to

How to determine Win32/Kryptik.HNFH?


File Info:

crc32: 60D255F5
md5: 99bad5961fa7e2f0fd78414d11908e15
name: 99BAD5961FA7E2F0FD78414D11908E15.mlw
sha1: e7129909c5825d636a0d34b4afd5f5561fbb5669
sha256: e20245e3a5fb8f9119c3ca78105615d5d2ba69e9406a64d7b024c1371d43cb07
sha512: 7c231ab404bb5f63f8ef711579c26f12df720aac0d5febea4794282c50aac5b0c7fbfca9dfcbd88adb80bf54dad53ac0283cad39e1922b55fb106c08d1cfe04b
ssdeep: 12288:VO/QPFKLbJLeoMPlOh3tsqThxsCiPenOdGbMmLj8gneZojAAdDwtUimsOXF:E/QmpuPmFxsCyVgb1HewDTf9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0512 0x00ac

Win32/Kryptik.HNFH also known as:

K7AntiVirusTrojan ( 00589fc61 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47337755
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 00589fc61 )
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FRX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNFH
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Trojan.Generic-9906244-0
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKD.47337755
ViRobotTrojan.Win32.Z.Sabsik.791040
MicroWorld-eScanTrojan.GenericKD.47337755
Ad-AwareTrojan.GenericKD.47337755
SophosMal/Generic-S + Troj/Krypt-DY
TrendMicroTROJ_GEN.R002C0PK821
McAfee-GW-EditionBehavesLike.Win32.Lockbit.bc
FireEyeGeneric.mg.99bad5961fa7e2f0
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Chapak
AviraTR/AD.GenSteal.ofgvg
Antiy-AVLTrojan/Win32.Chapak
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.RW!MTB
ArcabitTrojan.Generic.D2D2511B
GDataTrojan.GenericKD.47337755
AhnLab-V3Ransomware/Win.Stop.R448814
Acronissuspicious
VBA32BScope.Trojan.Sabsik.FL
MAXmalware (ai score=88)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PK821
RisingTrojan.Generic@ML.85 (RDML:IciIV2xCkx/4S3hhX6Y/zA)
YandexTrojan.Chapak!7oJ1SOe9gno
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLASNET.H
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HNFH?

Win32/Kryptik.HNFH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment