Malware

Should I remove “Win32/Kryptik.HIYK”?

Malware Removal

The Win32/Kryptik.HIYK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIYK virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
teslacartuning.com
ip-api.com

How to determine Win32/Kryptik.HIYK?


File Info:

crc32: D5C4B0E8
md5: b7829e555eb9cac99f404911dd3fd27b
name: B7829E555EB9CAC99F404911DD3FD27B.mlw
sha1: 6b5bd6ff95c2269ce0d46c559f63702201e532f7
sha256: e291b24d2e480fcf1df67d635e9f86f11f8193df3cc39381e37dab1a2a2c5988
sha512: fe5341ea31dca4b42a96253e2b04f7af29b1fd3a9803bf1ddb34395e3f41555c0df1f855cc3f745564ab78c2ec551f11d0ab934b21fe2ef424357e84b3f649ed
ssdeep: 12288:RK0uEHzo1aqGTOZpCLCI65E4lSCCi8nTcg5MUHHyUm+Gs:RLuEHqGTOaLAKCCi8pfHbm+Gs
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwalbifor.occ
FileVersion: 6.26.343
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.13.22
TranslationUsa: 0x0173 0x00e1

Win32/Kryptik.HIYK also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36198839
FireEyeGeneric.mg.b7829e555eb9cac9
McAfeeArtemis!B7829E555EB9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.ArchSMS.lsIq
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.GenericKD.36198839
K7GWTrojan ( 005768081 )
K7AntiVirusTrojan ( 005768081 )
BitDefenderThetaGen:NN.ZexaF.34780.FmKfamTl5UiG
CyrenW32/Kryptik.DBT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan.Win32.Chapak.eyrk
AlibabaTrojan:Win32/Chapak.df93d585
ViRobotTrojan.Win32.Z.Malpack.510464
Ad-AwareTrojan.GenericKD.36198839
EmsisoftTrojan.GenericKD.36198839 (B)
ComodoMalware@#22i6mrmy17bz0
F-SecureTrojan.TR/AD.VidarStealer.decxn
DrWebTrojan.Siggen11.59155
TrendMicroTROJ_FRS.0NA103AM21
McAfee-GW-EditionBehavesLike.Win32.RansomGandCrab.gc
SophosMal/Generic-S
IkarusTrojan.MalPack
eGambitUnsafe.AI_Score_97%
AviraTR/AD.VidarStealer.decxn
KingsoftWin32.Troj.Chapak.ey.(kcloud)
MicrosoftTrojan:Win32/Glupteba.KMG!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D22859B7
ZoneAlarmTrojan.Win32.Chapak.eyrk
GDataTrojan.GenericKD.36198839
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.C4306707
Acronissuspicious
VBA32Malware-Cryptor.InstallCore.6
ALYacTrojan.GenericKD.36198839
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIYK
TrendMicro-HouseCallTROJ_FRS.0NA103AM21
TencentWin32.Trojan.Chapak.Pgco
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIRY!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.f95c22
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.a5c

How to remove Win32/Kryptik.HIYK?

Win32/Kryptik.HIYK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment