Malware

Win32/Kryptik.HOKR removal guide

Malware Removal

The Win32/Kryptik.HOKR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HOKR virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.

How to determine Win32/Kryptik.HOKR?


File Info:

name: FE264349C7F70B4BED66.mlw
path: /opt/CAPEv2/storage/binaries/28cde8bb4d2992dc507ad09b8b34385ec6fc42478b75bb4391db43747afae16a
crc32: 68726B24
md5: fe264349c7f70b4bed661cb815a27464
sha1: 8ec310836555706ca3cd5dce65a930e002c5cf24
sha256: 28cde8bb4d2992dc507ad09b8b34385ec6fc42478b75bb4391db43747afae16a
sha512: 81b10064830a151be13e7a94a273a3abdc5ba5a35e9d43094075d773f6d948fb65d7c1a6be23ceb9c56012bc897bf1e9a5def4aad9d1c3c967572beb7e62cd94
ssdeep: 24576:41DwfHlGOADy7Kq1H1GV328e82fhjlDP97PJf8T1p+uX3i:41DwvlGOADy7RGV3Xe82ZjhP97V8TysS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186658E01F101A136F8B340BBCEFE552DDA68AA61130954E773D85A4F8BA2EF27D32157
sha3_384: f9dd761a619ec89c8538551085f1cddec63d3c44a6257d64fb255c64dfc1cba1f3ffb12c0999b1e3e4b4f3366854857a
ep_bytes: e878080000e97afeffffcc535733ff8b
timestamp: 2022-02-10 18:42:40

Version Info:

0: [No Data]

Win32/Kryptik.HOKR also known as:

LionicTrojan.Win32.Deyma.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.39062443
FireEyeGeneric.mg.fe264349c7f70b4b
McAfeeGenericRXRU-QB!FE264349C7F7
CylanceUnsafe
VIPRETrojan.GenericKD.39062443
K7AntiVirusTrojan ( 0058e5461 )
AlibabaTrojanDownloader:Win32/Deyma.36d29c0e
K7GWTrojan ( 0058e5461 )
CyrenW32/Wacatac.EB.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HOKR
KasperskyHEUR:Trojan-Downloader.Win32.Deyma.gen
BitDefenderTrojan.GenericKD.39062443
NANO-AntivirusTrojan.Win32.Deyma.jnaybg
CynetMalicious (score: 100)
AvastWin32:DangerousSig [Trj]
Ad-AwareTrojan.GenericKD.39062443
SophosMal/Generic-S + Troj/Dloadr-EGC
DrWebTrojan.DownLoader44.37277
ZillyaTrojan.Kryptik.Win32.3700152
TrendMicroTrojan.Win32.AMADEY.YXCBOZ
McAfee-GW-EditionGenericRXRU-QB!FE264349C7F7
EmsisoftMalCert-S.OC (A)
IkarusTrojan-Spy.Agent
GDataTrojan.GenericKD.39062443
JiangminTrojanDownloader.Deyma.acd
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.68D7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Deyma.ME!MTB
GoogleDetected
AhnLab-V3Trojan/Win.BotX-gen.R472397
VBA32TrojanDownloader.Deyma
ALYacTrojan.Downloader.Deyma.A
TrendMicro-HouseCallTrojan.Win32.AMADEY.YXCBOZ
RisingTrojan.MalCert!1.DBE1 (CLASSIC)
MaxSecureTrojan.Malware.74227175.susgen
FortinetW32/Kryptik.FKXJ!tr
AVGWin32:DangerousSig [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HOKR?

Win32/Kryptik.HOKR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment