Malware

Win32/Kryptik.HTTO removal guide

Malware Removal

The Win32/Kryptik.HTTO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HTTO virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Kryptik.HTTO?


File Info:

name: 2403CE130E001B3B4AB2.mlw
path: /opt/CAPEv2/storage/binaries/5947339d08c724fca10329ba2065e57b11670f576f014fbbd7e909faf172da8a
crc32: DF43CFF5
md5: 2403ce130e001b3b4ab2fd8363854a09
sha1: cc85d641fc99a9a0f67667dc0370348bcff4db81
sha256: 5947339d08c724fca10329ba2065e57b11670f576f014fbbd7e909faf172da8a
sha512: 150b26294a64529600fd71e603fe50e5739de384995e555bc33b488ed8d9d1e93871b4f2cf57e0b73e42829c68539e1bec0712a6a51f3af798411ea192f67477
ssdeep: 1536:kscgxqdEYB7kj1V5mF6+euYyqyhuWVFkVJcnag1QO43ClcXcKbuPx6:RF0danmp1YyqyhuWVFrag1t4qx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10B93AE227590C032EC974B3194F4CA615EB9F6210BA1C0B737AE4A7A5F503D19BB937E
sha3_384: 5b0ad9f5a818501f18aec7fe1194c730c9c45b25ec0b59ced88f5002cd25a5a5471f806313da6d368a5db2a1ed08946e
ep_bytes: e8ac240000e9a4feffff8bff566a0168
timestamp: 2023-06-07 20:43:10

Version Info:

Comments: Ceci est une application légitime.
CompanyName: Peugeot S.A.
FileDescription: Peugeot S.A. Produkt
FileVersion: 134
InternalName: ApplicationInterne
LegalCopyright: Droits d'auteur © Peugeot S.A. Tous droits réservés.
LegalTrademarks: Marques déposées © Peugeot S.A.
OriginalFilename: app.exe
ProductName: Application
ProductVersion: 134
Translation: 0x0407 0x04b0

Win32/Kryptik.HTTO also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Strab.4!c
MicroWorld-eScanTrojan.GenericKD.67426348
FireEyeTrojan.GenericKD.67426348
McAfeeArtemis!2403CE130E00
MalwarebytesTrojan.MalPack
SangforTrojan.Win32.Kryptik.V646
K7AntiVirusTrojan ( 005a0fff1 )
AlibabaTrojan:MSIL/Cryptos.0bba2935
K7GWTrojan ( 005a0fff1 )
VirITTrojan.Win32.GenusT.DMMX
CyrenW32/Agent.GJO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTTO
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Strab.gen
BitDefenderTrojan.GenericKD.67426348
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan.Cryptos.Zwhl
EmsisoftTrojan.GenericKD.67426348 (B)
F-SecureTrojan.TR/AD.Nekark.dhucq
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
GDataWin32.Packed.Kryptik.JEWAGZ
WebrootW32.Strab.Gen
AviraTR/AD.Nekark.dhucq
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Generic.D404D82C
ZoneAlarmHEUR:Trojan.Win32.Strab.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R585415
VBA32BScope.Backdoor.Agent
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0DF723
RisingTrojan.Kryptik!8.8 (TFE:1:rReHzpaluGD)
FortinetW32/GenKryptik.GHTO!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HTTO?

Win32/Kryptik.HTTO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment