Malware

About “Win32/Kryptik.HVFD” infection

Malware Removal

The Win32/Kryptik.HVFD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HVFD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial language used in binary resources: Saami
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Win32/Kryptik.HVFD?


File Info:

name: 502C4E8EC3D2D5ACE23C.mlw
path: /opt/CAPEv2/storage/binaries/03cfc0ae7e63ce6be63d1790d54e18c275e510df3c74e93fead0ba3dfe5d80a1
crc32: 60D9C6DC
md5: 502c4e8ec3d2d5ace23c9784ef4fbc88
sha1: 9b5e895496a1966453a16d9551431f5c9ec11ab1
sha256: 03cfc0ae7e63ce6be63d1790d54e18c275e510df3c74e93fead0ba3dfe5d80a1
sha512: c6263000be21b7d2fb7283a9e88b290b7eb5db86816bd71c27fed5ea71b19bafd0726377b417293de6aa6066f1a1e1251084d1b1bb72c226518d5bfd73ae5cad
ssdeep: 3072:63GGNoDyT2ZnhTeSUGm/chvzNFqmWIwhfoCgNSYPS/Ys5iDU29IJPgDYfJh9T:VfyTyZeSUG9L7qNIwZoCm4R4DU2+ysR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151641B1352E13C50E7668B328F6EE7E8370EF9518F2B7BB91218AE2F15719B1C162711
sha3_384: b75965fa339123386a2f4b921353d40779419a96ef1ae76ec00b7939d977b0b7aabc967e6825d445889ce6c9833dc3f9
ep_bytes: e8e4410000e989feffffff35c4f74200
timestamp: 2022-05-17 04:59:24

Version Info:

FileDescriptions: Butts
InternalName: Buckiyarana.exe
LegalCopyrights: Tultip feaver
LegalTrademark1: Gurumess
OriginalFilename: Buskobaser.exe
ProductVersion: 76.37.92.28
Translation: 0x0759 0x04e2

Win32/Kryptik.HVFD also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanTrojan.GenericKD.70287205
FireEyeGeneric.mg.502c4e8ec3d2d5ac
CAT-QuickHealRansom.Stop.P5
ALYacTrojan.GenericKD.70287205
MalwarebytesCrypt.Trojan.Malicious.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005adb851 )
BitDefenderTrojan.GenericKD.70287205
K7GWTrojan ( 005adb851 )
Cybereasonmalicious.496a19
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Smokeloader
ESET-NOD32a variant of Win32/Kryptik.HVFD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Ransomware.Tofsee-10013933-0
KasperskyHEUR:Trojan.Win32.Agent.gen
AlibabaRansom:Win32/StopCrypt.076df096
ViRobotTrojan.Win.Z.Agent.315392.GG
RisingTrojan.SmokeLoader!1.E66C (CLASSIC)
F-SecureTrojan.TR/Crypt.Agent.ftimw
DrWebTrojan.Siggen21.59051
VIPRETrojan.GenericKD.70287205
TrendMicroTrojan.Win32.SMOKELOADER.YXDKIZ
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ACJ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Stealerc.nz
VaristW32/Kryptik.LAC.gen!Eldorado
AviraTR/Crypt.Agent.ftimw
MAXmalware (ai score=84)
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Generic.D4307F65
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataTrojan.GenericKD.70287205
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R621085
VBA32BScope.Backdoor.Tofsee
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXDKIZ
TencentTrojan.Win32.Obfuscated.gen
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.771626.susgen
FortinetW32/Kryptik.HVEX!tr
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HVFD?

Win32/Kryptik.HVFD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment