Malware

What is “Win32/Kryptik.HLGN”?

Malware Removal

The Win32/Kryptik.HLGN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLGN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tttttt.me
apps.identrust.com

How to determine Win32/Kryptik.HLGN?


File Info:

crc32: 54C2A37F
md5: ef8efde9f631c28472193cae25a589ab
name: EF8EFDE9F631C28472193CAE25A589AB.mlw
sha1: cb8fd51a5ba43bbac56241f543020a0771bfc202
sha256: 67ee0a1422563807cb5af36dd2527d3e96f5532f34020c0cdacb4325d31d77b0
sha512: 17f25704c15a11e8e4e192e0ff71e9df7c87a39f562e6c937d3026d36e07a8699ee2e900f4974eaf74392903f0c27e63d6df33ee2e2a8026425155be577ea555
ssdeep: 12288:B+UQvsLI7PpCvyF8PZzTbvPHAV5Yya8nSq1Z5ChYwYNn:ApcA8vyCPRT7HAz88f1Z5Co
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersus: 10.0.9.5
ProductVersus: 10.0.6.5
Translations: 0x0365 0x0242

Win32/Kryptik.HLGN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057d9d61 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.65505
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0057d9d61 )
Cybereasonmalicious.a5ba43
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLGN
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.Win32.Racealer.gen
BitDefenderTrojan.GenericKD.37065268
MicroWorld-eScanTrojan.GenericKD.37065268
Ad-AwareTrojan.GenericKD.37065268
SophosMal/Generic-R + Troj/Kryptik-TR
BitDefenderThetaGen:NN.ZexaF.34722.HqW@aipZ0YlO
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
FireEyeGeneric.mg.ef8efde9f631c284
EmsisoftTrojan.GenericKD.37065268 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Racealer.cln
eGambitUnsafe.AI_Score_98%
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.QI!MTB
GDataTrojan.GenericKD.37065268
AhnLab-V3Trojan/Win.Glupteba.R424877
Acronissuspicious
McAfeePacked-GDT!EF8EFDE9F631
MAXmalware (ai score=86)
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#86% (RDMK:cmRtazoGVDo+55AalX/MyPqEvFLC)
IkarusWin32.Outbreak
FortinetW32/Kryptik.HLGH!tr
AVGWin32:PWSX-gen [Trj]

How to remove Win32/Kryptik.HLGN?

Win32/Kryptik.HLGN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment