Malware

Should I remove “Win32/Kryptik.HGXL”?

Malware Removal

The Win32/Kryptik.HGXL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGXL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by registry key

How to determine Win32/Kryptik.HGXL?


File Info:

name: 38BFF3F5815C16673FFC.mlw
path: /opt/CAPEv2/storage/binaries/b7f11fd5f8c9c4b31a589e5de44d01e9aca5f02bddc40c4dff1906a6cc9581ca
crc32: BB4419AD
md5: 38bff3f5815c16673ffcfedfbe16032d
sha1: c1302460ab296e259f2a388aeca048de3c0b5ac3
sha256: b7f11fd5f8c9c4b31a589e5de44d01e9aca5f02bddc40c4dff1906a6cc9581ca
sha512: 142a9e12dc40018e64891100d3e2ed8a257fbb7b40842d1454db2373d4c340fd4cfccf20cf8d224afac6c9fb686e23ce9c6f676d589a7388b14d49cade4fc856
ssdeep: 1536:c07N40Z9J+9lZPZ/niA7saUn728BtYW7eQksa2ce9JQukz57MCWxe:LNLa4Ag9nOWiQky9JXu572e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B3B3BF2276C3C9B2C54E157448E4DEA15BBE983013B949877BED26BF4FA43D0823735A
sha3_384: 3be689a7169f3e6d248838f391227df695ca92d779488ccf200708afa467ce98248f4ee314c5985be35f5898511f0e93
ep_bytes: e889260000e978feffff8bff558bec83
timestamp: 2019-06-29 00:37:35

Version Info:

Translations: 0x0218 0x00fd

Win32/Kryptik.HGXL also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
ClamAVWin.Dropper.Tofsee-9786992-0
FireEyeGeneric.mg.38bff3f5815c1667
McAfeeLockbit-FSUC!38BFF3F5815C
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00571a171 )
AlibabaTrojan:Win32/Zenpak.5645e933
K7GWTrojan ( 00571a171 )
Cybereasonmalicious.5815c1
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HGXL
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Zenpak.pef
BitDefenderGen:Heur.Mint.Titirez.gqW@W0Rx6usc
NANO-AntivirusTrojan.Win32.Zenpak.iaqdjn
MicroWorld-eScanGen:Heur.Mint.Titirez.gqW@W0Rx6usc
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Zenpak.Lmbn
Ad-AwareGen:Heur.Mint.Titirez.gqW@W0Rx6usc
SophosMal/Generic-S
ZillyaTrojan.Kryptik.Win32.2946616
TrendMicroBackdoor.Win32.GLUPTEBA.SMTH.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Heur.Mint.Titirez.gqW@W0Rx6usc (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Titirez.gqW@W0Rx6usc
JiangminTrojanRansom.Blocker.c
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1209913
MAXmalware (ai score=84)
ArcabitTrojan.Mint.Titirez.E23E9D
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Trojan/Win32.MalPe.R353640
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34742.gqW@a0Rx6usc
ALYacGen:Heur.Mint.Titirez.gqW@W0Rx6usc
VBA32Trojan.Wacatac
MalwarebytesTrojan.Glupteba
TrendMicro-HouseCallBackdoor.Win32.GLUPTEBA.SMTH.hp
RisingTrojan.Kryptik!1.CBE0 (CLASSIC)
IkarusTrojan.Win32.Tofsee
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HGYP!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A

How to remove Win32/Kryptik.HGXL?

Win32/Kryptik.HGXL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment