Malware

Win32/Kryptik.HNIA information

Malware Removal

The Win32/Kryptik.HNIA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNIA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HNIA?


File Info:

crc32: B471F5D8
md5: 9c64f888e0efc26ff7d429bc3eed1c2f
name: 9C64F888E0EFC26FF7D429BC3EED1C2F.mlw
sha1: 08c53580c7e0d8e2a44e61945163cf72c24ee182
sha256: ac7e21bafd6c77dae9d7aa171c315a0c94f598809e2366a18b1afc55d4a8e328
sha512: c4d6377fc8d4d9092a0d38795cf8c1d5af460a48dd3b76cc2c833ddb708f0dc2dd4cad74e4dd38020d48158c3f4dd8c546197c70b46844710acf8e3a4874a3e9
ssdeep: 6144:3OiqPssZdsqJvxfI8KwwYpEFYbs7qZXvGEqL4S7ITsq7igavwVf:K2A1IBww5FYCqQ4S79
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 15.54.17.21
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0184 0x046a

Win32/Kryptik.HNIA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 00584baa1 )
LionicTrojan.Win32.Convagent.j!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.113
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.80199
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/StopCrypt.ec58ea5f
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.0c7e0d
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecPacked.Generic.528
ESET-NOD32a variant of Win32/Kryptik.HNIA
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
ClamAVWin.Packed.Fragtor-9908420-0
KasperskyHEUR:Trojan.Win32.Injuke.gen
BitDefenderTrojan.GenericKDZ.80199
MicroWorld-eScanTrojan.GenericKDZ.80199
Ad-AwareTrojan.GenericKDZ.80199
SophosML/PE-A + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34294.uq0@auamGVdO
TrendMicroTROJ_GEN.R002C0PKF21
McAfee-GW-EditionBehavesLike.Win32.Emotet.fc
FireEyeGeneric.mg.9c64f888e0efc26f
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.drjd
AviraTR/AD.MalwareCrypter.yecrc
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.34D11BD
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/StopCrypt.MSK!MTB
GDataTrojan.GenericKDZ.80199
AhnLab-V3CoinMiner/Win.Glupteba.R450226
Acronissuspicious
McAfeeLockbit-FSWW!9C64F888E0EF
MAXmalware (ai score=89)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PKF21
RisingTrojan.Kryptik!1.DA8B (CLASSIC)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAT!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HNIA?

Win32/Kryptik.HNIA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment