Trojan

Trojan.Packed.Hiloti.Gen.3 removal instruction

Malware Removal

The Trojan.Packed.Hiloti.Gen.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Packed.Hiloti.Gen.3 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Packed.Hiloti.Gen.3?


File Info:

name: 79EE93DCD6D19F7026F2.mlw
path: /opt/CAPEv2/storage/binaries/f6dfab107dcbf2371db5caa36c6ec37919cbba10c9431a6a3fb3e8e45c0474c5
crc32: 186007A2
md5: 79ee93dcd6d19f7026f20a141c8608d7
sha1: 70654c6a17ec1de36c167302bc49c5c8b2f8e7d4
sha256: f6dfab107dcbf2371db5caa36c6ec37919cbba10c9431a6a3fb3e8e45c0474c5
sha512: 0969536c429d0c14e64c64a6c99f583bf9d32241d9f6f5b6a59e8629db098a39deb9649c9c5f847de7c6354207146568fc5a73969c6c1a14324726a63cc28ca7
ssdeep: 384:4ylW0Ab2X/NGvRBCJi4kV875bB/GB1FR:4y7X/svci/+/21FR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116828EA53974C040F5BE1B3B45EB910142A6FCA0194152C8F6D91F272E6FB94DF2267F
sha3_384: d6409c51aaf9c5e74887614417386998fa5421242504bfeca37051cea2194f88cc7682ad191b00223add6a51e1c3a8d5
ep_bytes: 558bec33f74e03d74a0bf803d6e8e200
timestamp: 2005-09-03 08:01:01

Version Info:

CompanyName: 15rmWIViMEwGJgrbyT
FileDescription: DVXgiqNv1al4A
FileVersion: hvB3CdaJwLrNtmVXrba
InternalName: iLkxlhDudSbAP
LegalCopyright: NWiFmV71rh6
OriginalFilename: qsmAamFa7ky
ProductName: p6NIkjO3fOci
ProductVersion: FnajQocQiESk
Translation: 0x0800 0x04b0

Trojan.Packed.Hiloti.Gen.3 also known as:

LionicHacktool.Win32.Krap.kZ3u
Elasticmalicious (high confidence)
DrWebTrojan.Packed.687
MicroWorld-eScanTrojan.Packed.Hiloti.Gen.3
FireEyeGeneric.mg.79ee93dcd6d19f70
ALYacTrojan.Packed.Hiloti.Gen.3
CylanceUnsafe
SangforHacktool.Win32.Obfuscator.GJ
K7AntiVirusTrojan ( 005223351 )
AlibabaVirTool:Win32/Obfuscator.bdc21b6c
K7GWTrojan ( 005223351 )
Cybereasonmalicious.cd6d19
BitDefenderThetaAI:Packer.01403E7A1F
VirITTrojan.Win32.Packed.BAL
CyrenW32/SuspPack.BH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Bredolab.AN
TrendMicro-HouseCallTROJ_BREDLAB.SMG
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Packed.Hiloti.Gen.3
NANO-AntivirusTrojan.Win32.TrjGen.dsjbaj
AvastWin32:Bredolab-AP [Trj]
TencentWin32.Trojan.Generic.Alji
Ad-AwareTrojan.Packed.Hiloti.Gen.3
EmsisoftTrojan.Packed.Hiloti.Gen.3 (B)
ComodoEmailWorm.Win32.Joleee.~J1@1su2y4
VIPRELooksLike.Win32.Malware!B (v)
TrendMicroTROJ_BREDLAB.SMG
McAfee-GW-EditionDownloader-CAQ
SophosML/PE-A + Mal/BredoPk-B
IkarusTrojan-Spy.Win32.Zbot
GDataTrojan.Packed.Hiloti.Gen.3
JiangminTrojanDownloader.Genome.vai
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Packed.Hiloti.Gen.3
MicrosoftTrojanDownloader:Win32/Waledac.C
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hiloti.Gen
Acronissuspicious
McAfeeDownloader-CAQ
VBA32Trojan.Zeus.EA.0999
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
RisingTrojan.Win32.Waledac.fq (CLOUD)
YandexTrojan.Bredolab.Gen!Pac.2
SentinelOneStatic AI – Malicious PE
AVGWin32:Bredolab-AP [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan.Packed.Hiloti.Gen.3?

Trojan.Packed.Hiloti.Gen.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment