Malware

Should I remove “Win32/Kryptik.HNWP”?

Malware Removal

The Win32/Kryptik.HNWP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNWP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.HNWP?


File Info:

name: 933C8B37850771D65014.mlw
path: /opt/CAPEv2/storage/binaries/28b2497a75ff3d7f6599bdd83b5a7cd29e63f554d0925027eb307703f4e1b675
crc32: 4B68CB14
md5: 933c8b37850771d6501443a5e0bea371
sha1: 48417f1e89720d377df1196653128a43c0ba62e1
sha256: 28b2497a75ff3d7f6599bdd83b5a7cd29e63f554d0925027eb307703f4e1b675
sha512: a14059c5b8379d7f0a2251adef326107704729f6cde65043a98cac9675e6e4451adf8f1379fb426fdd755025095ee3d466c1e6bcd9bf5f9a9b48696af5a1a659
ssdeep: 3072:rhWi5kJ3UkMeYI7ktprN/YBVTiz2QE0mAK8gITR2jHlqpsH0bteaO7FJjk1VSXon:rI2kMxIkFZYBVT1QLK831cFqpsH0HO7Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153F31363721AB53ACB22853205BE8E852673F78A7544DCBC71BC382D98AE3D3519F570
sha3_384: 99564fd8f304eba8d98d486eb20639dfbed66e64e3eaa5f81a30a132c1e68aa4ab1d91f2daa4ff2baf3711aab483ee3b
ep_bytes: 60be000042008dbe0010feff5789e58d
timestamp: 2021-11-23 02:18:13

Version Info:

0: [No Data]

Win32/Kryptik.HNWP also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.933c8b37850771d6
McAfeeRDN/Generic.rp
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0058ca7f1 )
BitDefenderThetaAI:Packer.35F283081F
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNWP
TrendMicro-HouseCallTROJ_GEN.R035C0WAU22
ClamAVWin.Malware.Trojanx-9876018-0
KasperskyHEUR:Trojan.Win32.Agent.vho
BitDefenderGen:Variant.Babar.27529
MicroWorld-eScanGen:Variant.Babar.27529
AvastWin32:Trojan-gen
TencentWin32.Trojan.Agent.Hqvc
Ad-AwareGen:Variant.Babar.27529
TrendMicroTROJ_GEN.R035C0WAU22
EmsisoftGen:Variant.Babar.27529 (B)
IkarusPUA.Win32.Prepscram
AviraHEUR/AGEN.1133398
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Babar.27529
AhnLab-V3Trojan/Win.SS.R468419
ALYacGen:Variant.Babar.27529
MAXmalware (ai score=83)
APEXMalicious
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazq2yt1JSGjXMcMqY7wtAFaL)
YandexTrojan.GenAsa!Iq6U1y//HFE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HISW!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.785077
PandaTrj/GdSda.A

How to remove Win32/Kryptik.HNWP?

Win32/Kryptik.HNWP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment