Malware

What is “Win32/Kryptik.HIIF”?

Malware Removal

The Win32/Kryptik.HIIF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIIF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HIIF?


File Info:

crc32: 430633CE
md5: 21b5ad4e6ce7954c8f23216890a431b0
name: 21B5AD4E6CE7954C8F23216890A431B0.mlw
sha1: 4c5bda837d2e5799bda514ca391c3df004fccd5f
sha256: fc0a714dcb0e371e62ef2acfa972da5f1842acaaadf6ac2fd20079ad8c26f048
sha512: dfc858b7fb03fa1ee191ac88ce9fb8ce8d17c8c200e32dcfd7fdbeede93b119ea9ee750748ca751bc33d8261ed61c7a598dae69d7ad77ea5319ce7845c199f5e
ssdeep: 98304:CKeVd2xWs7lQGOUgTcgtYpZ0if7o8+KR+kweng1N43Sstr79qQQQsTlC94xYojR:CKkoN7GMTR+Pe8NZUqQqYMYokFv9ozY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifes.acs
FileVers: 26.26.361
ProductVersion: 1.0.22
Copyright: Copyrighz (C) 2020, fadkafug
TranslationUsa: 0x0272 0x04d4

Win32/Kryptik.HIIF also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen11.55869
MicroWorld-eScanTrojan.GenericKD.35771784
FireEyeGeneric.mg.21b5ad4e6ce7954c
McAfeeGenericRXAA-FA!21B5AD4E6CE7
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00574dca1 )
BitDefenderTrojan.GenericKD.35771784
K7GWTrojan ( 00574dca1 )
BitDefenderThetaGen:NN.ZexaF.34700.@pKfaeA@!2oG
CyrenW32/Kryptik.CSM.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tofsee-9812536-0
KasperskyTrojan.Win32.Eb.bfl
AegisLabTrojan.Multi.Generic.4!c
Ad-AwareTrojan.GenericKD.35771784
EmsisoftTrojan.GenericKD.35771784 (B)
F-SecureTrojan.TR/AD.GoCloudnet.zvmgg
TrendMicroTrojanSpy.Win32.ARTEMIS.USMANLI20
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.zvmgg
MicrosoftTrojan:Win32/Glupteba.NR!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Bandit
ZoneAlarmTrojan.Win32.Eb.bfl
GDataTrojan.GenericKD.35771784
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R359493
Acronissuspicious
VBA32BScope.Trojan.Glupteba
ALYacTrojan.GenericKD.35771784
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.GS
ESET-NOD32a variant of Win32/Kryptik.HIIF
TrendMicro-HouseCallTrojanSpy.Win32.ARTEMIS.USMANLI20
RisingTrojan.Kryptik!8.8 (TFE:5:lg94y20lMtN)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIFA!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/RnkBend.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.00f

How to remove Win32/Kryptik.HIIF?

Win32/Kryptik.HIIF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment