Malware

Win32/Kryptik.HIVF (file analysis)

Malware Removal

The Win32/Kryptik.HIVF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIVF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HIVF?


File Info:

crc32: 1D9CFEF6
md5: ce31f1e5ea5951c790151fec2606daba
name: CE31F1E5EA5951C790151FEC2606DABA.mlw
sha1: f6ff74832c892f668ae887e23ecc4b18abfc514a
sha256: 898c957d6bc0417994827db79ca2c264ee100f0ccf54cafdbf18b4e9c9559c0b
sha512: 0b7c8659bfd00130b90d94a0fa22795244f791ed92c6e54298526638e0e8d6c9e237238e301de31bfb936589deb62a70e19dcfc59c7f21e857086c64e1e8d287
ssdeep: 6144:pph7jiXv2+G/+dCP70EiH8Wa1yA5NlMF8qXg/lvuMVHu7b:NqfJG/+U70H8/1J57MFJXOh7VO7
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.341
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.21
TranslationUsa: 0x0173 0x00e1

Win32/Kryptik.HIVF also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45482792
ALYacTrojan.GenericKD.45482792
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005763941 )
BitDefenderTrojan.GenericKD.45482792
K7GWTrojan ( 005763941 )
BitDefenderThetaGen:NN.ZexaF.34780.umKfaWoX6ggG
CyrenW32/Trojan.VMQA-4187
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIVF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Fugrafa-9821776-0
KasperskyTrojan.Win32.Zenpak.beoo
AlibabaBackdoor:Win32/Azorult.c12bd005
ViRobotTrojan.Win32.Z.Agent.330240.KK
TencentWin32.Trojan.Zenpak.Szuv
Ad-AwareTrojan.GenericKD.45482792
SophosMal/Generic-S
ComodoMalware@#2aje4pahju3aw
F-SecureTrojan.TR/Crypt.Agent.eihax
DrWebTrojan.DownLoader36.35412
TrendMicroTrojan.Win32.MALREP.THAAEBA
McAfee-GW-EditionBehavesLike.Win32.RansomGandCrab.fc
FireEyeGeneric.mg.ce31f1e5ea5951c7
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.45482792
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.eihax
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B60328
ZoneAlarmTrojan.Win32.Zenpak.beoo
MicrosoftTrojan:Win32/Azorult.MT!MTB
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRDN/RedLineStealer
MAXmalware (ai score=82)
VBA32BScope.Trojan.Azorult
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.MALREP.THAAEBA
RisingTrojan.Kryptik!1.D164 (CLASSIC)
IkarusTrojan.MalPack
FortinetW32/Kryptik.HIRY!tr
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/HEUR/QVM11.1.A4EB.Malware.Gen

How to remove Win32/Kryptik.HIVF?

Win32/Kryptik.HIVF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment