Malware

Win32/Kryptik.HIHM removal guide

Malware Removal

The Win32/Kryptik.HIHM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIHM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HIHM?


File Info:

crc32: E4AD0E4C
md5: 6fe32730613639ac8991417a2a972ddc
name: 6FE32730613639AC8991417A2A972DDC.mlw
sha1: 95e280fedaa51765ded6e6375ee524c29b954c8b
sha256: 0b176622e0def26acba58639181be6c5fd53773ae7d7387b9e0227b0eead4784
sha512: 26a51c8a15f6872ad5ca5d9439808c92129643f47805b7d520bf210d8f2896dd8a03e03467cc9b1caddf109a12bebcf4436d01bf3ce85ef00359eaf0e24c1799
ssdeep: 98304:F+gOS4RKvk3j0NEz25xrP9/MkAqoRrpzxNUx3o12mdS5BcEQKCl3OqnhmmNjE8a:s8fNEcxJ8rtU1ldI+ahnNjLPYkKQPOm
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2019, matrix
InternalName: reboot.exe
FileVersion: 1.0.5.4
ProductVersion: 1.7.6
Translation: 0x0409 0x04e8

Win32/Kryptik.HIHM also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.60881
MicroWorld-eScanTrojan.GenericKD.35749168
FireEyeGeneric.mg.6fe32730613639ac
Qihoo-360Generic/HEUR/QVM11.1.FAE7.Malware.Gen
ALYacTrojan.GenericKD.35749168
SangforMalware
K7AntiVirusTrojan ( 00574db21 )
BitDefenderTrojan.GenericKD.35749168
K7GWTrojan ( 00574db21 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34700.@pKfaCPCeTg
CyrenW32/Trojan.BCNY-5112
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Generic-9811131-0
KasperskyTrojan.Win32.AntiAV.czec
AlibabaTrojan:Win32/AntiAV.1c660b08
RisingTrojan.Ransom.GlobeImposter!1.AF70 (TFE:5:bYXJg1YG3DR)
Ad-AwareTrojan.GenericKD.35749168
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/AD.GoCloudnet.pgmez
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.pgmez
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/CryptInject!MSR
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2217D30
ZoneAlarmTrojan.Win32.AntiAV.czec
GDataTrojan.GenericKD.35749168
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R358467
Acronissuspicious
McAfeeGenericRXAA-AA!6FE327306136
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32a variant of Win32/Kryptik.HIHM
YandexTrojan.AntiAV!gF57X39Zwlw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.edaa51
Paloaltogeneric.ml

How to remove Win32/Kryptik.HIHM?

Win32/Kryptik.HIHM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment