Malware

Win32/Kryptik.HITT (file analysis)

Malware Removal

The Win32/Kryptik.HITT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HITT virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HITT?


File Info:

crc32: 81F60B7A
md5: c1207c8269736d9fb3936dd100177bc0
name: C1207C8269736D9FB3936DD100177BC0.mlw
sha1: d4e9e06ebe6d436db43ed1f25961842382b60514
sha256: 71cc2a35a7832c54d1cadc47897a11094fe404c970062ced193743f0fd0ef5f3
sha512: 8f245432217b8d2a16a9933853899f5946da9e1e729095e382d7f8bb70eee193171bd3389ea7b220e9ac83b04d434077a88bbe5a4c72f2b1c5f2e9a60f9e6e32
ssdeep: 6144:e1G3WVIOY6Bdjehj+qudd96ou/6mv5wdC:e1GmSafShjYdd96z/6cwdC
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2003-2005 Trend Micro Incorporated. All rights reserved.
InternalName: nnflaxnreh.exe
FileVersion: 8.82.4831
CompanyName: Trend Micro Incorporated
ProductName: NNFlaxnreh
ProductVersion: 8.82
FileDescription: CWShredder
OriginalFilename: nnflaxnreh.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.HITT also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Packed2.42802
MicroWorld-eScanTrojan.GenericKDZ.72503
FireEyeGeneric.mg.c1207c8269736d9f
CAT-QuickHealTrojan.DridexCS.S18241074
Qihoo-360HEUR/QVM39.1.999B.Malware.Gen
ALYacSpyware.Banker.Dridex
CylanceUnsafe
VIPRELooksLike.Win32.Dridex.e (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005765491 )
BitDefenderTrojan.GenericKDZ.72503
K7GWTrojan ( 005765491 )
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderThetaGen:NN.ZedlaF.34590.ou8@aaiGZhgi
CyrenW32/Dridex.AU.gen!Eldorado
SymantecPacked.Generic.517
TrendMicro-HouseCallTrojanSpy.Win32.DRIDEX.SMTHB
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Dridex-9822071-0
KasperskyTrojan.Win32.Agentb.bxne
NANO-AntivirusTrojan.Win32.Packed2.ihhgnj
RisingTrojan.Dridex!1.D160 (RDMK:cmRtazph+XySZ+9ucmRcmYBY3Qjl)
Ad-AwareTrojan.GenericKDZ.72503
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Crypt.Agent.ubsaf
ZillyaBackdoor.Dridex.Win32.431
TrendMicroTrojanSpy.Win32.DRIDEX.SMTHB
McAfee-GW-EditionDrixed-FKD!C1207C826973
SophosMal/EncPk-APX
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agentb.iqf
AviraTR/Crypt.Agent.ubsaf
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Dridex.RAX!MTB
GridinsoftTrojan.Win32.Packed.oa!s3
ArcabitTrojan.Generic.D11B37
ZoneAlarmTrojan.Win32.Agentb.bxne
GDataTrojan.GenericKDZ.72503
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dridex.C4299610
Acronissuspicious
McAfeeDrixed-FKD!C1207C826973
TACHYONTrojan/W32.Dridex.241664.C
MalwarebytesTrojan.Dridex
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HITT
TencentMalware.Win32.Gencirc.10ce3174
YandexTrojan.Agentb!TdSu0E1Qtpc
IkarusTrojan-Banker.Dridex
FortinetW32/GenKryptik.EJPK!tr
AVGWin32:BankerX-gen [Trj]

How to remove Win32/Kryptik.HITT?

Win32/Kryptik.HITT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment