Malware

Win32/Kryptik.HIPA information

Malware Removal

The Win32/Kryptik.HIPA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIPA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Tswana
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HIPA?


File Info:

crc32: A01A9637
md5: 0d00c0539454c994ff2c3f52f7a91c56
name: 0D00C0539454C994FF2C3F52F7A91C56.mlw
sha1: 368b6a7804e6ff8bb8ce6e9e16668573a5fd5849
sha256: b718f0d8e68217d9776830e1795fd3283a21706b0ab7cf8f0aad6b5a1cef8edf
sha512: 91eefca73df91c5ec9007c1e1c03af3bb94b6df1b18f2e5d72597eeb5dcee4ec31c5974de7c6bef0512dc634ac005a16d1fe95b238b2c84f2086817f7e7a8d17
ssdeep: 3072:47B30Qyf2YPYI7l2In+dlh4/YjLc02LV1mxrbKmN:MB30Pf2YAI5/n0lq/YfH2uKQ
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafull
ProductVersion: 1.0.15
TranslationUsa: 0x0273 0x007d

Win32/Kryptik.HIPA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36020322
CAT-QuickHealTrojan.Glupteba
Qihoo-360Generic/HEUR/QVM11.1.6EC7.Malware.Gen
ALYacTrojan.GenericKD.36020322
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 00575c2d1 )
BitDefenderTrojan.GenericKD.36020322
K7GWTrojan ( 00575c2d1 )
Cybereasonmalicious.804e6f
CyrenW32/Glupteba.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R03AC0DAA21
AvastWin32:TrojanX-gen [Trj]
KasperskyBackdoor.Win32.Mokes.alvv
AlibabaBackdoor:Win32/Mokes.658b3b3b
Ad-AwareTrojan.GenericKD.36020322
EmsisoftTrojan.GenericKD.36020322 (B)
DrWebTrojan.DownLoader36.33875
McAfee-GW-EditionBehavesLike.Win32.Trojan.dh
FireEyeGeneric.mg.0d00c0539454c994
SophosMal/Generic-S + Troj/Steal-AYV
SentinelOneStatic AI – Malicious PE
AviraTR/AD.SmokeLoader.vmqvn
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Glupteba.KMG!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D225A062
ZoneAlarmBackdoor.Win32.Mokes.alvv
GDataTrojan.GenericKD.36020322
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362198
Acronissuspicious
McAfeeGenericRXAA-AA!0D00C0539454
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIPA
RisingTrojan.Kryptik!8.8 (TFE:5:nt4Q08fYDcI)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.ERHN!tr
BitDefenderThetaGen:NN.ZexaF.34742.omKfaCj@MUeG
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HIPA?

Win32/Kryptik.HIPA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment