Malware

What is “Win32/Kryptik.HTYZ”?

Malware Removal

The Win32/Kryptik.HTYZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HTYZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.HTYZ?


File Info:

name: 8D7F895DA836E621F011.mlw
path: /opt/CAPEv2/storage/binaries/14b75854637aa0b881112e6b2b34d8d2087ee8fd20880e9bc4ba4d008946daa7
crc32: EEE01EDB
md5: 8d7f895da836e621f011cec83ee5d6f7
sha1: ed0153a61b317cbfa74af55f3121d4737e3103b4
sha256: 14b75854637aa0b881112e6b2b34d8d2087ee8fd20880e9bc4ba4d008946daa7
sha512: 322c8b47ddaff2e924abece335ee875eec6e6b1ec4d4176ed53397fbc5df09e6cef84e1367e955ba9cb1943a189aac0b7e3e3f56a13bd418a0d733e1f1ef6bff
ssdeep: 3072:99AzRJdhe/zq00girhyDbxZSjJ11K3omqyXi7bfPf95VH6lbr5yN8gY83wnHeWRU:99AC200fQE7Q3oPyX2Tnn1C0Gl+QdQB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15C54063D3E274572D9EA44727DFBD9CD6BAF264068E213F3160820FD1EC3A9414AB199
sha3_384: 1506b015ea87968c6858e0abc112fab66e21e5f16a9957cb11e58c79c6cc4537ee6cd127e85019193dd403215b5fbf87
ep_bytes: e8173c0000e9a4feffff3b0d3c014400
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: This is a legitimate application.
CompanyName: Georgian Bus Plant
FileDescription: Georgian Bus Plant Product
FileVersion: 367
InternalName: wZEJpJ6ueNIH
LegalCopyright: © Georgian Bus Plant All rights reserved.
LegalTrademarks: © Georgian Bus Plant Trademarks
OriginalFilename: Q2RedTgd.exe
ProductName: 13P4LuSrkb
ProductVersion: 367
Translation: 0x0407 0x04b0

Win32/Kryptik.HTYZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
AVGWin32:PWSX-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.67908012
FireEyeGeneric.mg.8d7f895da836e621
CAT-QuickHealTrojan.GenericPMF.S30390596
McAfeeRedline-FDQW!8D7F895DA836
Cylanceunsafe
ZillyaTrojan.Stealer.Win32.121108
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a75b91 )
AlibabaTrojanPSW:Win32/Stealer.2741be06
K7GWTrojan ( 005a75b91 )
BitDefenderThetaGen:NN.ZexaF.36348.rq2@aKBAD2ji
CyrenW32/Kryptik.KCN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTYZ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Pwsx-10005471-0
KasperskyTrojan-PSW.Win32.Stealer.bpeh
BitDefenderTrojan.GenericKD.67908012
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.10bf02da
EmsisoftTrojan.GenericKD.67908012 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PWS.RedLineNET.7
VIPRETrojan.GenericKD.67908012
TrendMicroTrojanSpy.Win32.REDLINE.YXDGBZ
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
SophosTroj/Krypt-AAD
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.5ETMBA
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Generic.D40C31AC
ZoneAlarmTrojan-PSW.Win32.Stealer.bpeh
MicrosoftTrojan:Win32/RedLineStealer.L!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R589507
VBA32Trojan.Injuke
ALYacTrojan.GenericKD.67908012
MalwarebytesTrojan.Crypt
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDGBZ
RisingTrojan.Kryptik!1.E841 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.W32.Injurer.gen
FortinetW32/Kryptik.HTVT!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HTYZ?

Win32/Kryptik.HTYZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment