Malware

Win32/Kryptik.HLIM malicious file

Malware Removal

The Win32/Kryptik.HLIM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLIM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

g-partners.in
peovon09.top
nailedpizza.top
iplogger.org

How to determine Win32/Kryptik.HLIM?


File Info:

crc32: FC0A3F91
md5: e8dea23ae7ad4a458af6b36a0fa5d77f
name: E8DEA23AE7AD4A458AF6B36A0FA5D77F.mlw
sha1: 7520881fb2f612379efa29f2a062e43c184944dd
sha256: 63d9527d69c228772ebadb63c1e74d7d0702acac52357fcea08ec5a408ca0453
sha512: 44b36de4858cf2c18acf84201e2956f7a0d5952e214e16caccba9d27f55aca6af2af79de95ec2481eeb0345a8206287f61baccc477885c56cc7b0f2dd7fd7789
ssdeep: 6144:zYJVHSd9LiK2KWz6OjhGsYDz2HQruFlwe7FEiGveq/kzC/:zYJVyDLiK2UOjpYc6uFlw8OZv5kz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0368 0x013b

Win32/Kryptik.HLIM also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader39.50493
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Bsymem
ALYacTrojan.GenericKDZ.75850
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Azorult.758be641
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fb2f61
CyrenW32/Kryptik.EHT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLIM
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Generic-9871308-0
KasperskyHEUR:Trojan.Win32.Bsymem.gen
BitDefenderTrojan.GenericKDZ.75850
MicroWorld-eScanTrojan.GenericKDZ.75850
Ad-AwareTrojan.GenericKDZ.75850
SophosMal/Generic-R + Troj/Kryptik-TR
ComodoMalware@#8t62r4hdcjv4
BitDefenderThetaGen:NN.ZexaF.34758.xyW@aKf4y9kG
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DFH21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fh
FireEyeGeneric.mg.e8dea23ae7ad4a45
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zenpak.hpk
AviraTR/AD.Chapak.iagct
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.RM!MTB
ArcabitTrojan.Generic.D1284A
AegisLabTrojan.Win32.Generic.lCNY
ZoneAlarmHEUR:Trojan.Win32.Bsymem.gen
GDataTrojan.GenericKDZ.75850
AhnLab-V3Trojan/Win.MalPE.R425660
Acronissuspicious
McAfeePacked-GDT!E8DEA23AE7AD
MAXmalware (ai score=89)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesTrojan.Crypt.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DFH21
RisingTrojan.Kryptik!1.D63F (CLASSIC)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HLIZ!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HLIM?

Win32/Kryptik.HLIM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment