Trojan

How to remove “Trojan.Crypt.HI”?

Malware Removal

The Trojan.Crypt.HI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Crypt.HI virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Crypt.HI?


File Info:

name: 7EB0422C481691863BC6.mlw
path: /opt/CAPEv2/storage/binaries/fa694eef623103b9b056a428378f4f1e8a5dcd06691a5b935f17e74ef0a457d1
crc32: 74285EEA
md5: 7eb0422c481691863bc66ba9afa4f8b2
sha1: 33dd279401f665b5e5d2e984654b72edce21fdc3
sha256: fa694eef623103b9b056a428378f4f1e8a5dcd06691a5b935f17e74ef0a457d1
sha512: 514fc065d42d4d7fef2452027a4cf74394fcd2cc6fccd12be6c9359519539111271e6a097e6ff2da5d13148bf8ee739561994ec3c2e64baa7efedf92bff0a42d
ssdeep: 3072:gAzGhwmMjba36cpdGop4qh05Ht71LcMqTZ+FqXs8cDNqR/nuK/ABslH0:gjwolpdGo+D5ttcx+F1rDYnz/AH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16434AE23B5F52D2BF9A02A751DEDFEA25E85BD40CF998A9373240FCD6B202950F10D16
sha3_384: 6912fee26ed124d01dfcb24753f4992604b469b0c815185a5af78b9118405662837f0e461cb0a282f53478130fce69c5
ep_bytes: 558bec6aff68f02f420068286f420064
timestamp: 2011-08-03 14:32:23

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: AntiVir Engine Module for Windows
FileVersion: 0, 0, 0, 0
InternalName: AntiVir/Win32
LegalCopyright: AntiVir? is a registered trademark of Avira GmbH, Germany
LegalTrademarks:
OriginalFilename: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
PrivateBuild:
ProductName: AVVDF
ProductVersion: 1, 0, 0, 1001
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan.Crypt.HI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.HI
FireEyeGeneric.mg.7eb0422c48169186
SkyhighBehavesLike.Win32.Infected.dh
ALYacTrojan.Crypt.HI
ZillyaTrojan.Farfli.Win32.1519
K7AntiVirusRiskware ( 0015e4f11 )
AlibabaBackdoor:Win32/Zegost.48e73772
K7GWRiskware ( 0015e4f11 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZexaF.36744.oi1@aygWRwdb
VirITTrojan.Win32.Agent_r.ALJ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.FB
APEXMalicious
ClamAVWin.Malware.Genpack-9841556-0
KasperskyBackdoor.Win32.Zegost.mtbkf
BitDefenderTrojan.Crypt.HI
NANO-AntivirusTrojan.Win32.Magania.bdkzqv
AvastWin32:Agent-AQGZ [Trj]
TencentWin32.Backdoor.Zegost.Xfow
EmsisoftTrojan.Crypt.HI (B)
F-SecureHeuristic.HEUR/AGEN.1341801
DrWebTrojan.DownLoader4.30871
VIPRETrojan.Crypt.HI
Trapminemalicious.moderate.ml.score
SophosTroj/YonSole-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PSW.Magania.aydl
WebrootW32.Backdoor.Gen
GoogleDetected
AviraHEUR/AGEN.1341801
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Hack.Zegost.mtbkf
MicrosoftBackdoor:Win32/Yonsole.B
XcitiumTrojWare.Win32.Farfli.fb@4km9kw
ArcabitTrojan.Crypt.HI
ZoneAlarmBackdoor.Win32.Zegost.mtbkf
GDataTrojan.Crypt.HI
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Magania.R13682
McAfeeGenericRXCP-AS!7EB0422C4816
MAXmalware (ai score=100)
VBA32BScope.TrojanDropper.Dinwod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Fednu!1.9928 (CLASSIC)
YandexTrojan.Farfli!KIckj0qJJM8
IkarusVirus.Win32.Vundo
MaxSecurenot-a-virus:HEUR:AdWare.Win32.Amonetize.fp
FortinetW32/Farfli.BVV!tr
AVGWin32:Agent-AQGZ [Trj]
Cybereasonmalicious.401f66
DeepInstinctMALICIOUS

How to remove Trojan.Crypt.HI?

Trojan.Crypt.HI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment