Malware

Win32/Kryptik.HKLY removal instruction

Malware Removal

The Win32/Kryptik.HKLY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKLY virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:14656
  • Unconventionial language used in binary resources: Spanish (Chile)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HKLY?


File Info:

crc32: 20DBDA02
md5: df7be3953c64d6dd2385ddef50c8d886
name: DF7BE3953C64D6DD2385DDEF50C8D886.mlw
sha1: 2215cecda3c69ce6fc8140d84536c6997d3f914f
sha256: 990d9606ca05c18755e8c36ba7dc798295f90be93eab8058c4a783fc339d7253
sha512: 998555696db62ecad71be050fce72c8a19b6a9e4f9ff3b85aa6b04db51a7a109b3ed31333446c5a381f9079e9b5ff3d481c6ea005fc6a968bc448563cb244be2
ssdeep: 98304:E6L4k30SVIS6minolVKldulTJM+C+PAQD5NS2KH5NFxe9IqwusvtsG4CFwJAJ6a:rP3r16mZyAlT17PA0NS2Ideerugoe7d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalNames: galimatimod
FileVersions: 7.0.2.54
LegalCopyrights: Wsekde
ProductVersions: 7.0.21.21
Translation: 0x0139 0x0c6b

Win32/Kryptik.HKLY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.36740344
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Azorult.04571676
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.da3c69
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKLY
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.36740344
MicroWorld-eScanTrojan.GenericKD.36740344
Ad-AwareTrojan.GenericKD.36740344
SophosMal/Generic-S + Troj/Kryptik-TR
BitDefenderThetaGen:NN.ZexaF.34678.@FW@a0XUDQT
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.df7be3953c64d6dd
EmsisoftTrojan.GenericKD.36740344 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.dgft
AviraTR/Crypt.Agent.rzcba
MicrosoftTrojan:Win32/Azorult.NN!MTB
GDataTrojan.GenericKD.36740344
AhnLab-V3Trojan/Win.MalPE.R416887
McAfeePacked-GBF!DF7BE3953C64
MAXmalware (ai score=80)
MalwarebytesTrojan.Crypt.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002H01DJ21
RisingExploit.Shellcode!8.2A (TFE:dGZlOgUq0Iy9xd9kog)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HKLZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.1.BA1B.Malware.Gen

How to remove Win32/Kryptik.HKLY?

Win32/Kryptik.HKLY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment