Malware

About “Win32/Kryptik.HIIN” infection

Malware Removal

The Win32/Kryptik.HIIN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIIN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HIIN?


File Info:

crc32: CD412704
md5: ccfa44b9fa02dabe3a1b1717056a4223
name: CCFA44B9FA02DABE3A1B1717056A4223.mlw
sha1: eaa9216e7e8bca3a514e648059febaa2f4581f1f
sha256: 6493c3cbd764f7812b77e7165eeb2cb37ab77f55757b229d0f8509c628c9c5f7
sha512: 5bf282e326846f1a43fd00cfdf12cc85ebd6720910e3bff354e387ddae191de30ae9dc69cf9b3b12632aae1ba753769939997f53f5e28219661df09414428daa
ssdeep: 98304:gGpN6hC3Uk1HM5ceQlOK/Mrd8lZDKxlpb1W7jcTCt8oeBxGgpPxSwrXVsovXAvY:gedi0OslxA1WMIeBJ7gYGjUqvZ8Dg4
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifes.acs
FileVers: 26.26.361
ProductVersion: 1.0.22
Copyright: Copyrighz (C) 2020, fadkafug
TranslationUsa: 0x0272 0x04d4

Win32/Kryptik.HIIN also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Spynet.48
MicroWorld-eScanTrojan.GenericKD.35771767
FireEyeGeneric.mg.ccfa44b9fa02dabe
CAT-QuickHealTrojan.Agent
McAfeeGenericRXAA-AA!CCFA44B9FA02
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.35771767
K7GWTrojan ( 00574e381 )
BitDefenderThetaGen:NN.ZexaF.34700.@pKfaSUfB6dG
CyrenW32/Kryptik.CSM.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Eb.bfo
Ad-AwareTrojan.GenericKD.35771767
EmsisoftTrojan.GenericKD.35771767 (B)
F-SecureTrojan.TR/AD.GoCloudnet.otilm
TrendMicroTrojanSpy.Win32.OUTBREAK.USMANLI20
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/AD.GoCloudnet.otilm
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Kryptik.vb
ArcabitTrojan.Bandit
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmTrojan.Win32.Eb.bfo
GDataTrojan.GenericKD.35771767
AhnLab-V3Malware/Win32.Generic.C4265936
Acronissuspicious
VBA32BScope.Trojan.Glupteba
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HIIN
TrendMicro-HouseCallTrojanSpy.Win32.OUTBREAK.USMANLI20
RisingTrojan.Kryptik!8.8 (TFE:5:fCIRPFtGjDU)
IkarusTrojan.Win32.Krypt
FortinetW32/Kryptik.HIFA!tr
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
Qihoo-360Win32/Trojan.582

How to remove Win32/Kryptik.HIIN?

Win32/Kryptik.HIIN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment