Malware

About “Win32/Kryptik.HIGR” infection

Malware Removal

The Win32/Kryptik.HIGR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIGR virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HIGR?


File Info:

crc32: 1ED6DE3F
md5: 3d50e3f57d38d117fbb6cf621f174fa1
name: 3D50E3F57D38D117FBB6CF621F174FA1.mlw
sha1: 4d8a51405f330735057db974e0a9d5692fbcca4c
sha256: a371787ee2019bd8585e46e9a7ddb4583fcfbe1cce328586cdaa396408e607f7
sha512: 60f47a8a3f4e37d24b67ecdbdf9ec7af6e6cbc2216564b8bbb9cbde687fa159e4e6fc422b4e81600dec478ee79ba171f75f17928457dc38f4169c0b425c85583
ssdeep: 98304:n1zlhhGJ4uFD0t0CopAIcadWMEP3Atxj1kkYBJrZpKOUr4cwDMeduJ2wTMWUvki:n1LhjuFD0t03vdte3c1EHsZrFwIpGvk
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019, matrix
InternalName: reboot.exe
FileVersion: 1.0.5.4
ProductVersion: 1.7.6
Translation: 0x0409 0x04e4

Win32/Kryptik.HIGR also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45030150
FireEyeGeneric.mg.3d50e3f57d38d117
Qihoo-360Generic/HEUR/QVM11.1.F81F.Malware.Gen
McAfeeGenericRXAA-AA!3D50E3F57D38
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 00574c331 )
BitDefenderTrojan.GenericKD.45030150
K7GWTrojan ( 00574c331 )
Cybereasonmalicious.05f330
BitDefenderThetaGen:NN.ZexaF.34700.@pKfa0na1Yp
CyrenW32/Trojan.KGRV-6154
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIGR
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.AntiAV.czdp
AlibabaTrojan:Win32/AntiAV.82966e23
Ad-AwareTrojan.GenericKD.45030150
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/AD.GoCloudnet.klmzm
DrWebTrojan.PWS.Stealer.29663
TrendMicroTrojanSpy.Win32.ARTEMIS.USMANLG20
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.klmzm
MAXmalware (ai score=80)
KingsoftWin32.Troj.Antiav.Cz.(kcloud)
MicrosoftTrojan:Win32/Coroxy.MR!MTB
GridinsoftTrojan.Win32.Packed.vb
ArcabitTrojan.Bandit
AhnLab-V3Malware/Win32.RL_Generic.R358611
ZoneAlarmTrojan.Win32.AntiAV.czdp
GDataTrojan.GenericKD.45030150
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Exploit.Shellcode
ALYacTrojan.GenericKD.45030150
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
TrendMicro-HouseCallTrojanSpy.Win32.ARTEMIS.USMANLG20
RisingTrojan.Ransom.GlobeImposter!1.AF70 (TFE:5:bYXJg1YG3DR)
YandexTrojan.GenAsa!A3rOJaxYS2w
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIFA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HIGR?

Win32/Kryptik.HIGR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment