Malware

Win32/Kryptik.HINO removal guide

Malware Removal

The Win32/Kryptik.HINO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HINO virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HINO?


File Info:

crc32: B6F1601F
md5: 89dc9089425bbc1c00fdabf8caa18403
name: 89DC9089425BBC1C00FDABF8CAA18403.mlw
sha1: fd323fe6a175c0a3b09c54a79b228335d06e345e
sha256: cf860f14fad97ba21bd92dec6820bf70e6f5baffe770f0e1f24dd100e4e97a6b
sha512: 950549c4c05837549a8a9285d53f8ce840ffd64ba75021269355302e5ba7c441fc8bc9819ea107653ac56113910b2b6a9267b0f20fa913cd154755553f94e905
ssdeep: 3072:JMw8Qv9azSLdL4rQZi3E1Y59GyOpVWQBd0KHOYWUGHKZ:JMRQv9nykZ+h3GyOpVWxCBG
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Win32/Kryptik.HINO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45331244
FireEyeGeneric.mg.89dc9089425bbc1c
McAfeeRDN/GenericM
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45331244
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34742.omKfaSYwbQiG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HINO
APEXMalicious
KasperskyHEUR:Trojan.Win32.Chapak.vho
AlibabaTrojan:Win32/Glupteba.5500cff2
TencentWin32.Trojan-qqpass.Qqrob.Edya
Ad-AwareTrojan.GenericKD.45331244
EmsisoftTrojan.GenericKD.45331244 (B)
F-SecureTrojan.TR/AD.SmokeLoader.ltfzz
TrendMicroTROJ_GEN.R06CC0DA821
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/AD.SmokeLoader.ltfzz
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Glupteba.NW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B3B32C
AhnLab-V3Trojan/Win32.Injector.R361893
ZoneAlarmHEUR:Trojan.Win32.Chapak.vho
GDataTrojan.GenericKD.45331244
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Caynamer
ALYacTrojan.GenericKD.45331244
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06CC0DA821
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.9425bb
AvastWin32:PWSX-gen [Trj]
Qihoo-360Generic/HEUR/QVM11.1.625B.Malware.Gen

How to remove Win32/Kryptik.HINO?

Win32/Kryptik.HINO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment