Malware

Win32/Kryptik.HINC information

Malware Removal

The Win32/Kryptik.HINC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HINC virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HINC?


File Info:

crc32: DE86C598
md5: 5fd36b431a0de1f7129d10127a3329e4
name: 5FD36B431A0DE1F7129D10127A3329E4.mlw
sha1: 1845891678718bf4bfbdaddc90e4340ecdac3289
sha256: ad594e3674b822f5575ab5edd599f1dc872c6956db2847a5bc2ec8308016e28d
sha512: c9ecb49b0e95d1b66fb12e01e61ad5701b6f4c00d3566a057239ffb0b9eb63def24936d71f2f07cff7b72798dda847cf4bae67c8f21170ce67c38bb6ed4e11e7
ssdeep: 3072:FvtbeSfTFnT5gkJ2cQS94+4D17Wkl2Lgd8pewzVbPbWzI/Rp5T:FvtXT5LJ2cB4DVp8gO1zVzlFT
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Win32/Kryptik.HINC also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35995550
FireEyeGeneric.mg.5fd36b431a0de1f7
ALYacTrojan.GenericKD.35995550
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00575a981 )
BitDefenderTrojan.GenericKD.35995550
K7GWTrojan ( 00575a981 )
Cybereasonmalicious.31a0de
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Chapak.exlz
AlibabaTrojan:Win32/Chapak.26e52573
ViRobotTrojan.Win32.Z.Malpack.236544
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
Ad-AwareTrojan.GenericKD.35995550
EmsisoftTrojan.GenericKD.35995550 (B)
F-SecureHeuristic.HEUR/AGEN.1140248
TrendMicroTROJ_GEN.R011C0DA721
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1140248
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.Llac.bdm
MicrosoftTrojan:Win32/Azorult.FW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2253F9E
ZoneAlarmTrojan.Win32.Chapak.exlz
GDataTrojan.GenericKD.35995550
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
McAfeeRDN/GenericM
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HINC
TrendMicro-HouseCallTROJ_GEN.R011C0DA721
TencentWin32.Trojan.Chapak.Tbix
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34742.omKfayXJNxnG
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.6047.Malware.Gen

How to remove Win32/Kryptik.HINC?

Win32/Kryptik.HINC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment