Malware

About “Win32/Kryptik.HIYU” infection

Malware Removal

The Win32/Kryptik.HIYU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIYU virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HIYU?


File Info:

crc32: 0C47D51C
md5: 782f98c00905f1b80f0dfc6dc287cd6e
name: 782F98C00905F1B80F0DFC6DC287CD6E.mlw
sha1: 6575caf3d68d899e83c4b352e985f86b53e804c7
sha256: 06040e1406a3b99da60e639edcf14ddb1f3c812993b408a8164285f2a580caaf
sha512: cd2a5e6f9d9f22cbf2e215d74dde5dbae107e14ac356bf47dfa4a4f1dd00d9399bf073bf67139a83a4bb29cd6e7081f832348ba6183aefd7a1faafceae890ed6
ssdeep: 3072:va99Ky1S0SD8MHjO73Ba01/H/7FlwZ2RJJBvX+WUE742Lg:vaGy1nS8MHi7xai73JtkWUEn0
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HIYU also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Emotet.1100
MicroWorld-eScanTrojan.GenericKD.45584109
FireEyeGeneric.mg.782f98c00905f1b8
ALYacTrojan.GenericKD.45584109
CylanceUnsafe
AegisLabHacktool.Win32.Krap.lKMc
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45584109
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.34780.vG5@aqgJZ6c
CyrenW32/Trojan.UBKY-6499
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-9822852-0
KasperskyTrojan-Banker.Win32.RTM.jma
AlibabaTrojanBanker:Win32/EmotetCrypt.fd7f2c0d
ViRobotTrojan.Win32.Emotet.351232
RisingTrojan.Emotet!8.B95 (TFE:5:jG3WLtYczKQ)
Ad-AwareTrojan.GenericKD.45584109
SophosMal/Generic-S
ComodoMalware@#t7f8r3nv6nyd
F-SecureTrojan.TR/AD.Emotet.pzctt
TrendMicroTROJ_FRS.0NA103AL21
McAfee-GW-EditionW32/PinkSbot-HJ!782F98C00905
EmsisoftTrojan.Emotet (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Emotet
AviraTR/AD.Emotet.pzctt
Antiy-AVLGrayWare/Win32.Kryptik.ehls
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/EmotetCrypt.V!MTB
GridinsoftTrojan.Win32.Emotet.oa
ArcabitTrojan.Generic.D2B78EED
ZoneAlarmTrojan-Banker.Win32.RTM.jma
GDataTrojan.GenericKD.45584109
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.C4305529
McAfeeW32/PinkSbot-HJ!782F98C00905
MAXmalware (ai score=97)
VBA32BScope.Malware-Cryptor.Emotet
MalwarebytesTrojan.Emotet
PandaTrj/Emotet.A
ESET-NOD32a variant of Win32/Kryptik.HIYU
TrendMicro-HouseCallTROJ_FRS.0NA103AL21
TencentWin32.Trojan.Falsesign.Aglj
IkarusTrojan-Banker.Emotet.Cert
FortinetW32/Emotet.1100!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM39.1.BF20.Malware.Gen

How to remove Win32/Kryptik.HIYU?

Win32/Kryptik.HIYU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment