Malware

How to remove “Win32/Kryptik.HTOY”?

Malware Removal

The Win32/Kryptik.HTOY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HTOY virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Kryptik.HTOY?


File Info:

name: 30D6DCE116D5560492E3.mlw
path: /opt/CAPEv2/storage/binaries/b7dd972151127adf89dceeaccafb512056af878d7e7aecd520e0ae6ae3d90d21
crc32: 83F7A85C
md5: 30d6dce116d5560492e3bbcd34183294
sha1: 6121a3165684da754ca45c62af1cc3216b4e19c6
sha256: b7dd972151127adf89dceeaccafb512056af878d7e7aecd520e0ae6ae3d90d21
sha512: 0666c6cb66fcd1b593df0b8f78ab6b266528c507887ccbd8fe7f36a134d7812cefd3f5ca7f6c8e9d6ce4ac85e121dda34eac5ce9b67d2b77e9cfc65d29b44162
ssdeep: 12288:VQ/5AJPqgriYXOl5nyPSSaf0NZrNPHyk/BAqgr0N:VS5AcMpXbSSafaqkWNrY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118454CD2309B4551D4600A3240FDE6A883233D7D5A5346DA71F8BF37BA3FA839A1E51B
sha3_384: eb19c16a623c135288310713eaace54294770450b3ce62de78156f8ec29dfbb7340849fb69f37c8c0db8919af8e7aa92
ep_bytes: e801080000e98efeffffff2548314200
timestamp: 2023-05-19 18:10:25

Version Info:

CompanyName: CK
FileDescription: CK
FileVersion: 1.0.0.1
InternalName: loader.exe
LegalCopyright: Copyright (C) 2023
OriginalFilename: CK
ProductName: CK
ProductVersion: 1.0.0.1
Translation: 0x0804 0x04b0

Win32/Kryptik.HTOY also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.67164776
FireEyeGeneric.mg.30d6dce116d55604
ALYacTrojan.GenericKD.67164776
MalwarebytesCrypt.Trojan.Malicious.DDS
SangforTrojan.Win32.Kryptik.Vlea
K7AntiVirusTrojan ( 005a5c181 )
K7GWTrojan ( 005a5c181 )
ArcabitTrojan.Generic.D400DA68
CyrenW32/ABRisk.DECQ-2530
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTOY
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.67164776
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan.FalseSign.Fplw
SophosGeneric Reputation PUA (PUA)
F-SecureAdware.ADWARE/Adware.Gen7
VIPRETrojan.GenericKD.67164776
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.67164776 (B)
JiangminTrojan.Banker.Bandra.xn
AviraADWARE/Adware.Gen7
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Trojan.PSE.P3253E
GoogleDetected
McAfeeArtemis!30D6DCE116D5
MAXmalware (ai score=81)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CEP23
RisingTrojan.Kryptik!8.8 (TFE:5:XpaHhxeDhCT)
YandexTrojan.Kryptik!zj422r6h//E
FortinetRiskware/Kryptik
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Kryptik.HTOY?

Win32/Kryptik.HTOY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment