Malware

Win32/Kryptik.HITD removal tips

Malware Removal

The Win32/Kryptik.HITD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HITD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HITD?


File Info:

crc32: E8FE5D43
md5: 4688bde3c41db9e124f0943b27b46af5
name: 4688BDE3C41DB9E124F0943B27B46AF5.mlw
sha1: bca2485bd7f8a3d1ea9a2f9cc5b817c699d0f5ac
sha256: 7d9dac810a5a9b18a6f3dfc5fd738bcfa84469dd71d7d3ce301a608cd0b82ed2
sha512: 7521663a0688c467e289e5c6b8ee16f603dc6b7b8c92d99da03527aa2264acf68d591b6c241945a4c0345f23225f6aa402c9680d36a7cdb10a89a6b17bd267c5
ssdeep: 98304:/pmCh8q/LlO8LgeT9gQFn5UBO3EP3vv5XtLLmGg5NN1QSqKlBDJofGYH75t65p/:fhJ36+EhZS5NN8KW3i2Qo1YU352u4C
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagude
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00dc

Win32/Kryptik.HITD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36099733
FireEyeGeneric.mg.4688bde3c41db9e1
McAfeeArtemis!4688BDE3C41D
CylanceUnsafe
ZillyaTrojan.Eb.Win32.330
AegisLabTrojan.Win32.Malicious.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36099733
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.GVAE-4675
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Fugrafa-9820299-0
KasperskyTrojan.Win32.Eb.bnj
AlibabaTrojan:Win32/Kryptik.7c091d85
ViRobotTrojan.Win32.Z.Kryptik.4469760
RisingTrojan.Kryptik!1.D164 (CLASSIC)
Ad-AwareTrojan.GenericKD.36099733
EmsisoftTrojan.GenericKD.36099733 (B)
F-SecureHeuristic.HEUR/AGEN.1122056
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WAG21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1122056
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Glupteba!ml
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D226D695
ZoneAlarmTrojan.Win32.Eb.bnj
GDataTrojan.GenericKD.36099733
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4298547
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34760.@pKfaeEPkcbG
ALYacTrojan.GenericKD.36099733
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HITD
TrendMicro-HouseCallTROJ_GEN.R002C0WAG21
TencentWin32.Trojan.Eb.Pdcq
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIRY!tr
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.811

How to remove Win32/Kryptik.HITD?

Win32/Kryptik.HITD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment