Malware

Win32/Kryptik.HING removal instruction

Malware Removal

The Win32/Kryptik.HING is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HING virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HING?


File Info:

crc32: 51C80BBB
md5: fb514208472abce242cfec86ff366f45
name: FB514208472ABCE242CFEC86FF366F45.mlw
sha1: 147866359a4be5e9c9b5a587cad6559d94aede28
sha256: 0c0b815dd9204336a9565905d4ab962bed2c110f3540203aeba1d037450ba585
sha512: 999e5428e089db68c9f142c2bb6832ae42d20690980e3fc1f7c2477cc7b7ee099c858fab479a989c6b8a70c769fc897d45d0a6b9fc479a542289563b386b4e61
ssdeep: 3072:FNbV4vSBHlrebketbxj0V21NC2r1sUjf2jhgBrya4U28wrb:3VJHxebkXO1FjetgB0Uar
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Win32/Kryptik.HING also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45328697
FireEyeGeneric.mg.fb514208472abce2
Qihoo-360Generic/HEUR/QVM11.1.612A.Malware.Gen
ALYacTrojan.GenericKD.45328697
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45328697
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8472ab
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyBackdoor.Win32.Mokes.altd
AlibabaBackdoor:Win32/Mokes.7743df58
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
Ad-AwareTrojan.GenericKD.45328697
EmsisoftTrojan.GenericKD.45328697 (B)
F-SecureTrojan.TR/Crypt.Agent.yzjxn
TrendMicroTROJ_GEN.R011C0DA721
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Glupteba
AviraTR/Crypt.Agent.yzjxn
Antiy-AVLTrojan/Win32.Llac.bdm
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B3A939
ZoneAlarmBackdoor.Win32.Mokes.altd
GDataTrojan.GenericKD.45328697
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=81)
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HING
TrendMicro-HouseCallTROJ_GEN.R011C0DA721
TencentWin32.Backdoor.Mokes.Eegv
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.HIFA!tr
BitDefenderThetaGen:NN.ZexaF.34742.omKfaWNG59iG
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HING?

Win32/Kryptik.HING removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment