Malware

Win32/Kryptik.HLDO (file analysis)

Malware Removal

The Win32/Kryptik.HLDO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLDO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HLDO?


File Info:

crc32: 427C6A4A
md5: 600a9bfff38e3949762d34448a2d1fb9
name: 600A9BFFF38E3949762D34448A2D1FB9.mlw
sha1: 7747e239695b64c3f89178fc562426cf343900e4
sha256: 9a3652f2ae0372d7ebf9a4f2002ddf16d1e11c70fc623df581a117deddf6542a
sha512: b67764abbcf9edee7356966c322d6f40d95e0cb780aa195a068d23775902eb7e431af65e6e2d85748d30dc9f0fbe52dc610e80a2e5758b3a422a3ac7b454b38d
ssdeep: 12288:lbh8bChcqY+o64lToacqVTfsh9hVYOaEAItLt:cWhcj+o64lEapZsh9hvaUt5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HLDO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37009648
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/SpyNoon.4d8b5cf6
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9695b6
CyrenW32/Trojan.ELPR-2032
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Kryptik.HLDO
ZonerTrojan.Win32.111659
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyVHO:Backdoor.Win32.Convagent.gen
BitDefenderTrojan.GenericKD.37009648
ViRobotTrojan.Win32.Z.Wacatac.517120
MicroWorld-eScanTrojan.GenericKD.37009648
Ad-AwareTrojan.GenericKD.37009648
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.adtte@0
BitDefenderThetaGen:NN.ZexaE.34692.FuW@a0AjxMfi
TrendMicroTrojan.Win32.NOON.USMANEV21
McAfee-GW-EditionBehavesLike.Win32.Emotet.hc
FireEyeGeneric.mg.600a9bfff38e3949
EmsisoftTrojan.GenericKD.37009648 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_88%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/SpyNoon.SS!MTB
AegisLabTrojan.Win32.Convagent.m!c
GDataTrojan.GenericKD.37009648
AhnLab-V3Trojan/Win.Kryptik.C4504477
Acronissuspicious
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=84)
VBA32BScope.Trojan.Agent
MalwarebytesMalware.AI.1850730742
TrendMicro-HouseCallTrojan.Win32.NOON.USMANEV21
RisingTrojan.Generic@ML.90 (RDMK:/13WqB9XeXp/NPTEgkokHA)
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLASNET.H
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HLDO?

Win32/Kryptik.HLDO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment