Malware

Win32/Kryptik.HLBS removal tips

Malware Removal

The Win32/Kryptik.HLBS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLBS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Tunisia)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HLBS?


File Info:

crc32: 5C566C49
md5: 1a4c96515b10859b7053a4f717b61608
name: 1A4C96515B10859B7053A4F717B61608.mlw
sha1: ba141d261cf8ee1f33cfb0c4c820d840850e781b
sha256: f2a7cc00ce9933490e51df2d5df9e7b0b2165c73297a9fa8a99fbf51b85926b8
sha512: c0743b15628637e403072d291d099d919382e05cb701a601ebac5703adf4c78b064918ec3050c122862c1e5fc6933123309028881c6e49d7b42c1a94200835d0
ssdeep: 12288:cp7+nEFn89BZUuMt9Jn9NzOUbrVEAe8zdk16al6eseqGEYWbChoUpi5TO:cpQEFvDJ9NiU/Te8zdO6m6JeYCho+i5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersus: 1.0.55.28
ProductVersus: 1.0.55.28
Translations: 0x0285 0x02a7

Win32/Kryptik.HLBS also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.61cf8e
CyrenW32/Kryptik.EED.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLBS
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Gandcrypt-9865160-0
KasperskyHEUR:Trojan-PSW.Win32.Racealer.gen
BitDefenderTrojan.GenericKD.36982115
MicroWorld-eScanTrojan.GenericKD.36982115
Ad-AwareTrojan.GenericKD.36982115
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34692.UqW@aKqzDkfG
McAfee-GW-EditionBehavesLike.Win32.Emotet.bc
FireEyeGeneric.mg.1a4c96515b10859b
EmsisoftGen:Variant.Jaik.46103 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Glupteba.QE!MTB
AegisLabTrojan.Win32.Malicious.4!c
GDataTrojan.GenericKD.36982115
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=81)
VBA32BScope.Trojan.Crypt
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H07ER21
RisingTrojan.Kryptik!1.D63F (CLOUD)
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HLBO!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.HLBS?

Win32/Kryptik.HLBS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment