Malware

Win32/Kryptik.HIQA information

Malware Removal

The Win32/Kryptik.HIQA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIQA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Portuguese
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HIQA?


File Info:

crc32: B3721054
md5: f0c86d27b27d44d11e5dc4c6a738bb1b
name: F0C86D27B27D44D11E5DC4C6A738BB1B.mlw
sha1: 7f3a5211fab648ba198afbde8c9ea69bf7b2352a
sha256: f46fcddaca56f561247347a71dc3a6db6b03ea42325497fa2cff9a7c29411b9d
sha512: 522552455663bbcc245be6727418c57626e450d370aec2e89d8803d3736a1470aa9aa97c257cbeea2b1b22461860f8e9e11d344916e73ec98bbb06789cce7323
ssdeep: 98304:9h+0e+S4Oqzmo8lTG0AiZ8b51XgV09xybj5XDlB+Hs3yDqFl0d3dx5JA+sfMddB:9kWDzQ1ZA1XgVyHD73+U6BKVpz
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debag.ekze
Prod: 1.2.2
FileVersions: 1.0.5.8
LegalCo: Copyri (C) 2019, permudationzy

Win32/Kryptik.HIQA also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.f0c86d27b27d44d1
McAfeeArtemis!F0C86D27B27D
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2821079
SangforMalware
K7AntiVirusTrojan ( 00575dce1 )
BitDefenderTrojan.GenericKD.45391612
K7GWTrojan ( 00575dce1 )
Cybereasonmalicious.1fab64
CyrenW32/Trojan.VJGV-7753
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Zenpak.bddb
AlibabaBackdoor:Win32/Glupteba.4a406cda
MicroWorld-eScanTrojan.GenericKD.45391612
RisingTrojan.Kryptik!8.8 (TFE:5:kaNjoczJ6H)
Ad-AwareTrojan.GenericKD.45391612
SophosMal/Generic-S
ComodoMalware@#2x1o3o2ukcqoy
F-SecureTrojan.TR/AD.GoCloudnet.jzijp
DrWebTrojan.Siggen11.57755
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.F0CBC0UAJ21
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
EmsisoftTrojan.GenericKD.45391612 (B)
IkarusTrojan.Crypt
JiangminExploit.ShellCode.bgf
AviraTR/AD.GoCloudnet.jzijp
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Glupteba.NY!MTB
GridinsoftRansom.Win32.Wacatac.oa
ArcabitTrojan.Generic.D2B49EFC
ZoneAlarmTrojan.Win32.Zenpak.bddb
GDataTrojan.GenericKD.45391612
AhnLab-V3Malware/Win32.RL_Tofsee.R362453
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34780.@pGfaeZ0lHpG
ALYacTrojan.GenericKD.45391612
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/Agent.JMA
ESET-NOD32a variant of Win32/Kryptik.HIQA
TrendMicro-HouseCallTROJ_GEN.F0CBC0UAJ21
TencentWin32.Trojan.Zenpak.Ects
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.HGHW!tr
WebrootW32.Trojan.Gen
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM11.1.77BD.Malware.Gen

How to remove Win32/Kryptik.HIQA?

Win32/Kryptik.HIQA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment