Malware

Win32/Kryptik.HJPL removal tips

Malware Removal

The Win32/Kryptik.HJPL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HJPL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Tatar
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HJPL?


File Info:

crc32: 84D2B1D0
md5: 398738411e74c6f79d780671ae2f3de8
name: 398738411E74C6F79D780671AE2F3DE8.mlw
sha1: 33920862c2e00f2cc80ece55d84370711beb0186
sha256: 676593610aafb444bd3b06028cbe14c0f1bb08d621da061609436d0afbe536fb
sha512: f402cb6eeb82a069d974b485653a6dd28ddaf8ff78fb6ff5683c38921af418db99eeb7a75f468f975327d359f51ac17aafe36c4a00c7efae78b5218a0c9053c3
ssdeep: 6144:eax5JiI/gvZM6CUvHSoJ27cSG4xtwXCzhwqB0f5s6wS/fMT:eaD0I/gvZMmvH1PS/cCNcf/7E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: calinilimodumator.exe
FileVersions: 7.0.0.23
LegalCopyrights: Vsekdag
ProductVersions: 67.0.20.45
Translation: 0x0409 0x22fc

Win32/Kryptik.HJPL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45771521
FireEyeGeneric.mg.398738411e74c6f7
CAT-QuickHealTrojan.Multi
ALYacSpyware.Infostealer.RedLine
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Stealer.l!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.45771521
K7GWHacktool ( 700007861 )
Cybereasonmalicious.2c2e00
BitDefenderThetaGen:NN.ZexaF.34590.xG0@ae2ir4cG
CyrenW32/Trojan.RCBY-8298
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
AlibabaTrojanSpy:Win32/Azorult.6a4bd792
RisingSpyware.Stealer!8.3090 (CLOUD)
Ad-AwareTrojan.GenericKD.45771521
EmsisoftTrojan.Crypt (A)
ComodoMalware@#2ntbji3dcmi86
F-SecureTrojan.TR/Crypt.ZPACK.pxxwd
DrWebWin32.HLLW.Autoruner1.52920
TrendMicroTrojan.Win32.MALREP.THBBCBA
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.fh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.pxxwd
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.MZ!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2BA6B01
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataTrojan.GenericKD.45771521
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4345920
Acronissuspicious
McAfeePacked-GBF!398738411E74
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HJPL
TrendMicro-HouseCallTrojan.Win32.MALREP.THBBCBA
TencentWin32.Trojan-spy.Stealer.Llhn
IkarusTrojan.WinGo.Ranumbot
eGambitUnsafe.AI_Score_84%
FortinetW32/GenKryptik.FCCE!tr
WebrootW32.Trojan.D6
AVGWin32:BotX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Generic.HwoCd9sA

How to remove Win32/Kryptik.HJPL?

Win32/Kryptik.HJPL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment