Malware

Win32/Kryptik.HINU removal tips

Malware Removal

The Win32/Kryptik.HINU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HINU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HINU?


File Info:

crc32: C611F221
md5: ac261c197b6bd4b8d316b6ef74bb407a
name: AC261C197B6BD4B8D316B6EF74BB407A.mlw
sha1: cbf3bb6b3377bcc6b2188299917b257a1df0f3f1
sha256: 52e190d5e6928c29afab4f808a8c33990ce22b35d2d94758583dec9665b7cc04
sha512: e9a54021992ab2c4e5470623e5877295824db6e91c15dcc2baf645da964fd3e37c4c2018fcf7f32598c47364b37b2a5cc1609b1eed2a707a93f6e28f82adda21
ssdeep: 3072:TuJKnNpvV5eij6kkCyDX1tNn2oi8RCIgmme8zDF0ywwxE6yr:TWKH/eiFlyDOt1Te8l0y5x7yr
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x053a

Win32/Kryptik.HINU also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36001278
ALYacTrojan.GenericKD.36001278
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 00575ab91 )
BitDefenderTrojan.GenericKD.36001278
K7GWTrojan ( 00575ab91 )
Cybereasonmalicious.97b6bd
BitDefenderThetaGen:NN.ZexaF.34742.omKfaWEnLPgG
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyBackdoor.Win32.Mokes.altx
AlibabaBackdoor:Win32/Mokes.b39ecb9c
RisingTrojan.Kryptik!8.8 (TFE:5:M4loB2xS0kQ)
Ad-AwareTrojan.GenericKD.36001278
EmsisoftTrojan.GenericKD.36001278 (B)
ComodoMalware@#54i9fcujhz34
F-SecureTrojan.TR/AD.SmokeLoader.rfwap
TrendMicroTROJ_GEN.R023C0DA821
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
FireEyeGeneric.mg.ac261c197b6bd4b8
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.SmokeLoader.rfwap
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Llac.bdm
MicrosoftTrojan:Win32/Azorult.FW!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D22555FE
ZoneAlarmBackdoor.Win32.Mokes.altx
GDataTrojan.GenericKD.36001278
AhnLab-V3Trojan/Win32.Injector.R361893
Acronissuspicious
McAfeeArtemis!AC261C197B6B
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.HINU
TrendMicro-HouseCallTROJ_GEN.R023C0DA821
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_93%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HINU?

Win32/Kryptik.HINU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment