Malware

Win32/Kryptik.HIKL removal guide

Malware Removal

The Win32/Kryptik.HIKL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIKL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HIKL?


File Info:

crc32: CC9D434E
md5: a1dee75a66d6ad292c2523f6c6fcd0bc
name: A1DEE75A66D6AD292C2523F6C6FCD0BC.mlw
sha1: 1cd17e139f712287fb0decaeb893dcfb1a049541
sha256: b96dd9954f0bdc6986ebb9f62c42d1b8872b278d1717a114141d3fea5e281363
sha512: fb8d09e760d55f180fb599cc3be6c7705860c8dd90494f4fd07fbc8ff73ec4664134366429c3e14f71ea0f95ec4354d2b6b6e818d98a93f4ccb9a40ec3d110d7
ssdeep: 12288:2jt6kPuJauljX7dkTZoKv6dDYudQ86hMDlJ92MLR22xl3u7xhJsivnULc4bTouV:2x6kPuPlrKv6dtoO792Mtxl+7xfsivn
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: reboud.exe
Product: 1.7.6
FileVersions: 1.0.5.4
LegalCo: Copyri (C) 2019, patrition
Translation: 0x5439 0x00fa

Win32/Kryptik.HIKL also known as:

Elasticmalicious (high confidence)
McAfeeArtemis!A1DEE75A66D6
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
Cybereasonmalicious.39f712
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIKL
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
DrWebTrojan.Siggen11.56422
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.jc
FireEyeGeneric.mg.a1dee75a66d6ad29
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.AutoHotkey.61LCQA
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34700.RmGfaGlWq1gc
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.MalPack.GS
FortinetW32/Kryptik.HFSR!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM11.1.251F.Malware.Gen

How to remove Win32/Kryptik.HIKL?

Win32/Kryptik.HIKL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment