Trojan

TrojanDownloader:Win32/Hicrazyk.A removal instruction

Malware Removal

The TrojanDownloader:Win32/Hicrazyk.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Hicrazyk.A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive

How to determine TrojanDownloader:Win32/Hicrazyk.A?


File Info:

name: BADCE24E2C72267FCB9C.mlw
path: /opt/CAPEv2/storage/binaries/6e5a3c35926f72ba40b88695d7a1caaf76fbb8688e47e22f3bfd21b350a68208
crc32: 42B2D3B9
md5: badce24e2c72267fcb9c10e9cc3d44d1
sha1: e82e716a1a81596704d7880c10373d6eb36a7327
sha256: 6e5a3c35926f72ba40b88695d7a1caaf76fbb8688e47e22f3bfd21b350a68208
sha512: a9e4381cda4bc929a5bf361d6bcbcb4241b74e912e49e42a4e1104d6540cb143c712c5c481fe81a1d22fa8e5fbf12abd89f68822e9756ddafb675461b68b8cb4
ssdeep: 3072:ZS17XJiDxmJT1W5O09iagZYnCKtpRZxG7O+fraQJo3KgW:ZGibo09V8Et0nHrgW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9D30207F6D1ADA7D5A20A7429F3A772E7FB6D4003740E176F9C3FAB2E316404909582
sha3_384: 4b7c3e30e57c4fde07ef23a69fb373b54a5931af66651a0a44fa76ab06f7a9540770837c3f6664290425f80af50214b9
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2008-11-20 20:28:21

Version Info:

Comments: http://yu.zjcg.org
CompanyName: MeinV
FileDescription: Installer Application
FileVersion: 1.0.2.4
LegalCopyright: Corporation. All rights reserved.
ProductName: 31978_2663506514771
ProductVersion: 1.0.2.4
Translation: 0x0000 0x03a8

TrojanDownloader:Win32/Hicrazyk.A also known as:

AVGNSIS:Downloader-AAW [Adw]
DrWebAdware.Downware.2283
MicroWorld-eScanTrojan.Downloader.Hicrazyk.A
FireEyeTrojan.Downloader.Hicrazyk.A
CAT-QuickHealTrojanDownloader.NSIS.Hicrazy
SkyhighBehavesLike.Win32.Dropper.cc
ALYacTrojan.Downloader.Hicrazyk.A
Cylanceunsafe
SangforDownloader.NSIS.Hicrazyk.Vq4n
AlibabaTrojanDownloader:Win32/Hicrazyk.7f970c5e
CrowdStrikewin/malicious_confidence_90% (W)
SymantecTrojan.Gen
ESET-NOD32NSIS/TrojanDownloader.Grinidou.I
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Trojan.Hicrazyk-12
Kasperskynot-a-virus:Downloader.NSIS.Agent.fc
BitDefenderTrojan.Downloader.Hicrazyk.A
NANO-AntivirusTrojan.Nsis.Agent.cvzngl
AvastNSIS:Downloader-AAW [Adw]
TencentNsis.Trojan-Downloader.Ader.Fkjl
EmsisoftTrojan.Downloader.Hicrazyk.A (B)
F-SecureHeuristic.HEUR/AGEN.1338359
BaiduNSIS.Trojan-Downloader.Grinidou.a
VIPRETrojan.Downloader.Hicrazyk.A
TrendMicroTROJ_GEN.R002C0DB724
Trapminemalicious.moderate.ml.score
SophosMal/NsisDl-A
SentinelOneStatic AI – Suspicious PE
VaristW32/Chindo.S.gen!Eldorado
AviraHEUR/AGEN.1338359
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.AdLoad.gen
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojanDownloader:Win32/Hicrazyk.A
ArcabitTrojan.Downloader.Hicrazyk.A
ZoneAlarmnot-a-virus:Downloader.NSIS.Agent.fc
GDataTrojan.Downloader.Hicrazyk.A
GoogleDetected
McAfeeArtemis!BADCE24E2C72
VBA32suspected of Trojan.Downloader.gen
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DB724
IkarusTrojan-Downloader.NSIS.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/StartPage.NY!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Grinidou.I

How to remove TrojanDownloader:Win32/Hicrazyk.A?

TrojanDownloader:Win32/Hicrazyk.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment