Malware

Win32/Kryptik.HITV malicious file

Malware Removal

The Win32/Kryptik.HITV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HITV virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HITV?


File Info:

crc32: A3FEED76
md5: 87a22e868fbb1ab3c78c86bc881d4b07
name: 87A22E868FBB1AB3C78C86BC881D4B07.mlw
sha1: 53a1cec80e19ce499e1a43c539c79fa86596e6bd
sha256: fbde87dbaf78f5f818e6187756fe88fa4a4741af9e0d64590ae1fcb96f610835
sha512: e7a350ddca1f6d1aec11de6a12a9956e9a6dcfeef9bf0b8557de89b21da22076079eec32572c234c35163b1c9098074878af32a6a5e9dd6aa13e24afb213701c
ssdeep: 98304:AULzqJkukmuLwIPJhIxkIg8DDoX10vwvXdHek9006nbqCYqOdtSyHpb4DXYHZb/:AQckxh6BDDwvXdHn90M4AyoR/iKDtgf
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Win32/Kryptik.HITV also known as:

Elasticmalicious (high confidence)
ClamAVWin.Dropper.Glupteba-9819602-0
MalwarebytesTrojan.MalPack.GS
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.80e19c
BitDefenderThetaGen:NN.ZexaF.34760.@pKfauvHaWbG
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
CynetMalicious (score: 100)
AlibabaTrojan:Win32/Kryptik.959d882f
MicroWorld-eScanTrojan.AntiSandbox.GenericKDS.36106862
Ad-AwareTrojan.AntiSandbox.GenericKDS.36106862
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.ZYX.USMANAF21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.rc
FireEyeGeneric.mg.87a22e868fbb1ab3
EmsisoftTrojan.AntiSandbox.GenericKDS.36106862 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Glupteba
AviraHEUR/AGEN.1122056
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Glupteba.KM!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.AntiSandbox.GenericS.D226F26E
AegisLabHacktool.Win32.ArchSMS.lsxE
ZoneAlarmTrojan.Win32.Eb.bnt
GDataTrojan.AntiSandbox.GenericKDS.36106862
AhnLab-V3Trojan/Win32.Kryptik.C4300033
Acronissuspicious
VBA32BScope.Trojan.Azorult
TACHYONTrojan/W32.BrsecmonE.5060608.B
ESET-NOD32a variant of Win32/Kryptik.HITV
TrendMicro-HouseCallTrojanSpy.Win32.ZYX.USMANAF21
TencentWin32.Trojan.Eb.Ecak
IkarusTrojan.Win32.Krypt
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.978F.Malware.Gen

How to remove Win32/Kryptik.HITV?

Win32/Kryptik.HITV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment