Malware

Win32/Kryptik.HGIQ removal instruction

Malware Removal

The Win32/Kryptik.HGIQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGIQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r3—sn-4g5e6nzz.gvt1.com

How to determine Win32/Kryptik.HGIQ?


File Info:

crc32: 71EDAFC3
md5: 3ec8b040fb99156912222b5d1ca89f89
name: 3EC8B040FB99156912222B5D1CA89F89.mlw
sha1: ddf2e63fcfb023e71c1956f39ce2c03a03734d59
sha256: 4e0173650c7511fac33742838884241225dd1a1919b6c26304220d47ea2c1eb0
sha512: 0b346f0b5a5cc35fbe6be24eae59709aca70ae62f6fa0f8d61548e9413c52aa045f751a277cbece8cd62fe93ea1b9433411a887353693fac17a19c944e277bde
ssdeep: 3072:jrERTnvVLh3ibmBFBNYOUDXCGZhiOtXtcQoORcRG7GbXFj9AhwbuNWkjMKr:8VtLUbQTUDSgi8RcRGSR9mwEdo0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0808 0x04b0

Win32/Kryptik.HGIQ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Ransom.GandCrab.Gen.2
FireEyeGeneric.mg.3ec8b040fb991569
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ransom.GandCrab.Gen.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWin.Packed.Gandcrab-6552923-4
K7AntiVirusTrojan ( 0053305e1 )
BitDefenderTrojan.Ransom.GandCrab.Gen.2
K7GWTrojan ( 0053305e1 )
Cybereasonmalicious.0fb991
BitDefenderThetaGen:NN.ZexaF.34590.puX@aGkGk9bO
CyrenW32/S-06a2b15e!Eldorado
SymantecPacked.Generic.525
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Packed.Gandcrab-6552923-4
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Encoder.fctwcf
ViRobotTrojan.Win32.GandCrab.Gen.A
TencentMalware.Win32.Gencirc.10b5489c
Ad-AwareTrojan.Ransom.GandCrab.Gen.2
SophosML/PE-A + Troj/GandCrab-J
ComodoTrojWare.Win32.Fuerboos.DG@7o67qa
F-SecureHeuristic.HEUR/AGEN.1121545
DrWebTrojan.Encoder.24384
ZillyaTrojan.GandCrypt.Win32.247
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Ransom.GandCrab.Gen.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.dp
AviraHEUR/AGEN.1121545
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.GandCrypt
MicrosoftTrojan:Win32/GandCrypt.PVP!MTB
ArcabitTrojan.Ransom.GandCrab.Gen.2
SUPERAntiSpywareRansom.GandCrab/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Ransom.GandCrab.Gen.2
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Gandcrab.Exp
Acronissuspicious
McAfeeTrojan-FPOH!3EC8B040FB99
TACHYONRansom/W32.GandCrab
VBA32BScope.TrojanDownloader.Upatre
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HGIQ
TrendMicro-HouseCallMal_HPGen-37b
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.GenAsa!7j4w/sASx3U
IkarusTrojan-Ransom.GandCrab
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.CNAR!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Ransom.ec9

How to remove Win32/Kryptik.HGIQ?

Win32/Kryptik.HGIQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment