Malware

Win32/Kryptik.HIIQ (file analysis)

Malware Removal

The Win32/Kryptik.HIIQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIIQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • A process sent information about the computer to a remote location.

Related domains:

api.ipify.org
peasseal.com

How to determine Win32/Kryptik.HIIQ?


File Info:

crc32: 839EAF09
md5: 2565301bc06fb030600bbb4251b0e7c7
name: 2565301BC06FB030600BBB4251B0E7C7.mlw
sha1: 683736d02019a31b06e9fe961010d30e1e9f0bbe
sha256: 2074ad2dc62a398d62ab1f91d446ca269a4bc1cb5cbd5a677904afbf2d3685e0
sha512: 6434da67a169826b80df48ca4d30b54ab3673c1bf66224ae745ec81f4ca3e169f866c7e3327c75307794c55523de4f970afa63964be10bf96bd7eb03126ce549
ssdeep: 3072:XliHgqVX64MdLQM/oNOlAQ1SQ7eSYPqU6/WrR5VgBEh7rjuU+TO+fJ5/bFegtoB:XKgqVX64GP/okc6kTgBYLuUsOqLshPy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Courselove Corporation. All rights reserved
InternalName: Paragraph Decimal
FileVersion: 7.7.6.728
CompanyName: Courselove Corporation
ProductName: Courselovexae Develop evenxae
ProductVersion: 7.7.6.728
FileDescription: Courselove Develop even
OriginalFilename: second.dll
Translation: 0x0409 0x04b0

Win32/Kryptik.HIIQ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45051513
FireEyeTrojan.GenericKD.45051513
ALYacTrojan.Agent.Hancitor
AegisLabTrojan.Win32.Geral.a!c
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.45051513
K7GWTrojan ( 00574e691 )
K7AntiVirusTrojan ( 00574e691 )
CyrenW32/Trojan.KNBS-5406
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIIQ
KasperskyHEUR:Trojan-Downloader.Win32.Geral.gen
AlibabaTrojanDownloader:Win32/Hancitor.f0d8a3b0
Ad-AwareTrojan.GenericKD.45051513
SophosMal/Generic-S
ComodoMalware@#1z8enltsmpb1w
F-SecureTrojan.TR/AD.ZDlder.zoodb
DrWebTrojan.Chanitor.63
TrendMicroTROJ_GEN.R002C0DLL20
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.45051513 (B)
IkarusTrojan.Win32.Krypt
WebrootW32.Trojan.Gen
AviraTR/AD.ZDlder.zoodb
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Hancitor.ARK!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2AF6E79
AhnLab-V3Malware/Win32.Generic.C4266248
ZoneAlarmHEUR:Trojan-Downloader.Win32.Geral.gen
GDataTrojan.GenericKD.45051513
CynetMalicious (score: 100)
McAfeeArtemis!2565301BC06F
MalwarebytesSpyware.FickerStealer
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DLL20
RisingTrojan.GenKryptik!8.AA55 (TFE:5:dKK11KLTivU)
YandexTrojan.GenKryptik!z6Tm6Ed7hY4
FortinetW32/GenKryptik.EYPU!tr
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
Qihoo-360Win32/Trojan.c96

How to remove Win32/Kryptik.HIIQ?

Win32/Kryptik.HIIQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment