Malware

Win32/Kryptik.HODR removal

Malware Removal

The Win32/Kryptik.HODR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HODR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Macedonian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HODR?


File Info:

name: A73AC2832E24421BBF35.mlw
path: /opt/CAPEv2/storage/binaries/e826a49823a330e9db285fe74c84d37adb4925cb5cfd0dd630bfeacdc1e599f2
crc32: CB2B1CA3
md5: a73ac2832e24421bbf35948db8177ef5
sha1: a96057b67ce91ce52b5d97661aa0689bb3411f37
sha256: e826a49823a330e9db285fe74c84d37adb4925cb5cfd0dd630bfeacdc1e599f2
sha512: a217d3d977d1d97d6402cb52bbbea5cab40e845d85e5caffecaa59a73e7fa41142f31ec7ce9550042174c60d21ceb661db02e6ff32eb3ae89e4f173ffad3f1d2
ssdeep: 6144:vlYclVDKs5FBfzL898989898989898989898989898989898989898989898989V:t7TOsrBfz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104C68441A7F4D826F6F71A70547892D92A37FCE66835828EB0543B1B2CB27D25DB0723
sha3_384: d4c050c54540574d8169975e27941d4843e78471996491e523cd2140c461a9eb739ae2a60e3170caabb59fc3c486d166
ep_bytes: e813450000e978feffff8bff558bec81
timestamp: 2020-10-04 11:32:29

Version Info:

FileVers: 65.51.36.16
ProductVersa: 7.50.25.71
InternalName: peatemas
LegalCopyrighd: sharmir
Translation: 0x0169 0x0300

Win32/Kryptik.HODR also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83172
FireEyeGeneric.mg.a73ac2832e24421b
McAfeePacked-GBE!A73AC2832E24
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058d8fd1 )
BitDefenderTrojan.GenericKDZ.83172
K7GWTrojan ( 0058d8fd1 )
Cybereasonmalicious.67ce91
BitDefenderThetaGen:NN.ZexaF.34182.@t0@aCusYenG
CyrenW32/Kryptik.FXH.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HODR
ClamAVWin.Malware.Generic-9937750-0
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
Ad-AwareTrojan.GenericKDZ.83172
SophosML/PE-A
DrWebTrojan.Siggen16.38200
ZillyaTrojan.Kryptik.Win32.3682572
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.wt
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.GenericKDZ.83172 (B)
APEXMalicious
Antiy-AVLTrojan/Generic.ASMalwS.351A388
MicrosoftRansom:Win32/StopCrypt.PAS!MTB
GDataTrojan.GenericKDZ.83172
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Stop.R468727
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
ALYacTrojan.GenericKDZ.83172
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingBackdoor.Tofsee!8.1E9 (RDMK:cmRtazqoyMIlD9cGS/xyxdOzem1H)
YandexTrojan.Kryptik!AcIxCFP7yh0
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HODR!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32/Kryptik.HODR?

Win32/Kryptik.HODR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment