Malware

Win32/Kryptik.HIPN removal instruction

Malware Removal

The Win32/Kryptik.HIPN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIPN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
ip.anysrc.net

How to determine Win32/Kryptik.HIPN?


File Info:

crc32: DF2ECF81
md5: 2e02b2f45ac3c4e5a2d12eb797486e1d
name: 2E02B2F45AC3C4E5A2D12EB797486E1D.mlw
sha1: cab699a445b74a12f1c731af58b8c6b7ac952564
sha256: 592b9726261928827cbb9d04445fd7deeb556ecec0b40a3be6265ca2e260b4fd
sha512: f8499f2d9942abdace37def892ef1a97ed50b4cf0346a2027229c166a3b639b7f7ea1fa0218d5becb9d419b6529d33571942ac71fedcbae7d03d304706b7d7a7
ssdeep: 6144:koMgXsS8vVr0uBuz7KGW3yv8/fk2SvpLBxGxDDhKg9T0/Q1HN29GBPJs780YWmPL:kopx2ou0aY40/yU4Rs7MWcZP
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HIPN also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72388
FireEyeGeneric.mg.2e02b2f45ac3c4e5
Qihoo-360Win32/Trojan.04c
ALYacTrojan.GenericKDZ.72388
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00575b4c1 )
AlibabaRansom:Win32/KlopRansom.174
K7GWTrojan ( 00575b4c1 )
Cybereasonmalicious.45ac3c
BitDefenderThetaGen:NN.ZexaF.34742.BmX@aqRJV0hi
CyrenW32/Trojan.DUYS-5008
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R023C0DA921
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Deapax.gen
BitDefenderTrojan.GenericKDZ.72388
ViRobotTrojan.Win32.Trickbot.442368.A
APEXMalicious
Ad-AwareTrojan.GenericKDZ.72388
EmsisoftTrojan.GenericKDZ.72388 (B)
F-SecureTrojan.TR/Redcap.ecqji
DrWebTrojan.Packed.140
McAfee-GW-EditionBehavesLike.Win32.Trickbot.gm
SophosMal/Generic-S (PUA)
IkarusTrojan.SuspectCRC
GDataTrojan.GenericKDZ.72388
JiangminTrojan.Deapax.ad
AviraTR/Redcap.ecqji
Antiy-AVLTrojan/Win32.Kryptik
GridinsoftMalware.Win32.Gen.oa
ArcabitTrojan.Generic.D11AC4
ZoneAlarmHEUR:Trojan.Win32.Deapax.gen
MicrosoftTrojan:Win32/TrickBotCrypt.PX!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4290563
Acronissuspicious
McAfeeTrickbot-FTGZ!2E02B2F45AC3
VBA32Malware-Cryptor.InstallCore.6
MalwarebytesTrojan.TrickBot
AvastWin32:TrojanX-gen [Trj]
ESET-NOD32a variant of Win32/Kryptik.HIPN
RisingTrojan.Generic@ML.80 (RDML:JjrKk3U690Q6XhnqGYGtIg)
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.KCKB!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HIPN?

Win32/Kryptik.HIPN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment