Malware

Win32/Kryptik.HCIV removal instruction

Malware Removal

The Win32/Kryptik.HCIV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCIV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Rhaeto (Romance)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

aurumboy.com

How to determine Win32/Kryptik.HCIV?


File Info:

crc32: F2B51B45
md5: 3e891f8c7f098c7163859328eeedc3b5
name: installspod.exe
sha1: 50636d6ecba8cc0f1c21a94ad7937aae2fc9b6c9
sha256: 3d48ada5b6341deaba10ce5acca068d2484e4509e8b348968cd5839fe8e948b8
sha512: e98b38bf1e3a17cce2ba5552e43c5dab1ed14e00f7f5bd47741da8670346eb2bd6aa2b58e0bca2623384369af81cc9e420f0da2948b909c61d44225c9b97c4a3
ssdeep: 3072:/mcBldtdupDBNPG5IpQ+ZiKPxWuadjX/bWOUbbA4qhu7C:/hApNpQbN1bfeba
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HCIV also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33583227
Qihoo-360Win32/Trojan.PSW.624
McAfeeArtemis!3E891F8C7F09
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.GenericKD.33583227
K7GWTrojan ( 005639b41 )
K7AntiVirusTrojan ( 005639b41 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HCIV
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Racealer.efh
SUPERAntiSpywareRansom.GandCrab/Variant
TencentWin32.Trojan-qqpass.Qqrob.Lnev
Ad-AwareTrojan.GenericKD.33583227
EmsisoftTrojan.GenericKD.33583227 (B)
F-SecureTrojan.TR/Crypt.Agent.dshuv
DrWebTrojan.Siggen9.30972
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Worm.ch
FortinetW32/Kryptik.HCIM!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3e891f8c7f098c71
SophosMal/RyPack-A
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.BVRA-0023
AviraTR/Crypt.Agent.dshuv
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D200707B
ZoneAlarmTrojan-PSW.Win32.Racealer.efh
MicrosoftPWS:Win32/Predator.KM!MTB
AhnLab-V3Trojan/Win32.MalPe.R330696
Acronissuspicious
ALYacTrojan.GenericKD.33583227
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R01FH0CD120
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_96%
GDataTrojan.GenericKD.33583227
BitDefenderThetaGen:NN.ZexaF.34104.mqW@aSUI6gkG
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]

How to remove Win32/Kryptik.HCIV?

Win32/Kryptik.HCIV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment