Malware

Win32/Kryptik.HUXU removal tips

Malware Removal

The Win32/Kryptik.HUXU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HUXU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.HUXU?


File Info:

name: 62873965621CAF8C3548.mlw
path: /opt/CAPEv2/storage/binaries/afecde0bdbb6a948c85332b537963ab3d375a3fe90c40b256af5fd31f2cb3d16
crc32: 4E5620B7
md5: 62873965621caf8c3548869dbf98dafb
sha1: b14acd76a02693067558270642591891407b1707
sha256: afecde0bdbb6a948c85332b537963ab3d375a3fe90c40b256af5fd31f2cb3d16
sha512: 3e88f823e48d30d5a204c64e53ddf74af4835f5ec8cf2b52e2ea7fb2b83ae029e6eceb9c93eaf0f42b967535f6fb0033d9598b8441ea5e3f543ed21f30529c38
ssdeep: 196608:d+IQpE9GiozXefCHQt5i+hRnTv1j8g8s6svimVmKgn:dlEmfGnORnTv1l6Zm7Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1118602227FE09577D17313359A9EF27930ADE5700B3AC1D723851F1C7A302A396296AB
sha3_384: 9e787ae8b335707e42c90ee5c79d13243d41902007f36ccd5e18e63f90f7c4c29560d308c85143a829730c5b278a5081
ep_bytes: e8410c0000e98efeffff3b0d04105d00
timestamp: 2017-08-14 09:01:08

Version Info:

CompanyName: O&O Software GmbH
FileDescription: O&O AdViewer
FileVersion: 9.4.0.0
InternalName: OOAdViewer.exe
LegalCopyright: Copyright O&O Software GmbH
OLESelfRegister: no
ProductName: O&O AdViewer
ProductVersion: 9.4.4
Comments:
Translation: 0x0409 0x04b0

Win32/Kryptik.HUXU also known as:

BkavW32.Common.4E75C4B6
CyrenCloudRisk/WIN_PE.afecde0b!Threatlookup
Elasticmalicious (high confidence)
SkyhighArtemis
McAfeeArtemis!62873965621C
Cylanceunsafe
ZillyaTrojan.Shella.Win32.145
K7AntiVirusTrojan ( 005ad92e1 )
AlibabaTrojan:Win32/Kryptik.a3ae7353
K7GWTrojan ( 005ad92e1 )
ESET-NOD32a variant of Win32/Kryptik.HUXU
CynetMalicious (score: 99)
AvastWin32:Malware-gen
F-SecureTrojan.TR/Crypt.Agent.voaae
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
GoogleDetected
AviraTR/Crypt.Agent.voaae
MicrosoftTrojan:Win32/Wacatac.B!ml
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Generic@AI.84 (RDML:JCxkBps31eM/YDy4cddwXw)
MaxSecureTrojan.Malware.3411146.susgen
FortinetW32/GenKryptik.GONM!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HUXU?

Win32/Kryptik.HUXU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment