Malware

Should I remove “Win32/Kryptik.HRAA”?

Malware Removal

The Win32/Kryptik.HRAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HRAA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/Kryptik.HRAA?


File Info:

name: 5C92467EB6C390D2FD9B.mlw
path: /opt/CAPEv2/storage/binaries/596c884d04fd210525e236639745a7fa6eb0c1e9611178523d796d25633fcc96
crc32: D1E3DE0B
md5: 5c92467eb6c390d2fd9b590147c4d669
sha1: 6572f5239147139a7863aac6441895018758b0a6
sha256: 596c884d04fd210525e236639745a7fa6eb0c1e9611178523d796d25633fcc96
sha512: af906f3def39543bac48890a0579f87ba3e60985a01339fbc59a1848ea1d6e19ac70d060864994fc340063b8fd00803ec0ac1ebffc79fc4b950135a975c846c8
ssdeep: 3072:o8z3uInR0Y3t1hDQJq2EeHK7LoTVPsnRm:/o4NQKSK7kTRsn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137D3F1317D90CC71F01272B61966C6A1BA7EFC115AA14A9B77252BAE4F301C1AA3F347
sha3_384: 4a21f5437cf5a97e38d44e3cb5d0fbafe9b5db7da522c5e5741f00eccd60a14a727f8dd55d8ef0470d3d3910a8aae990
ep_bytes: e8a1170000e978feffff8bff558bec81
timestamp: 2021-06-09 10:48:43

Version Info:

Translations: 0x0148 0x0079

Win32/Kryptik.HRAA also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.62475422
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaPacked:Application/Obfuscated.25059786
Cybereasonmalicious.391471
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HRAA
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Packed.gen
BitDefenderTrojan.GenericKD.62475422
AvastWin32:PWSX-gen [Trj]
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Worm.cc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.5c92467eb6c390d2
EmsisoftTrojan.GenericKD.62475422 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftRansom:Win32/StopCrypt!ml
GDataWin32.Trojan-Downloader.SmokeLoader.CR4V3F
GoogleDetected
AhnLab-V3Packed/Win.GEE.R524330
Acronissuspicious
McAfeePacked-GEE!5C92467EB6C3
MAXmalware (ai score=99)
VBA32Malware-Cryptor.2LA.gen
TrendMicro-HouseCallTROJ_GEN.R002H06J222
RisingTrojan.Generic@AI.90 (RDML:UO4cQR/e40JksPXv5zAYQQ)
IkarusTrojan-Ransom.StopCrypt
FortinetW32/Kryptik.HACT!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HRAA?

Win32/Kryptik.HRAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment