Malware

What is “Win32/Kryptik.HLLQ”?

Malware Removal

The Win32/Kryptik.HLLQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLLQ virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

www.bing.com
authd.feronok.com
app.bighomegl.at

How to determine Win32/Kryptik.HLLQ?


File Info:

crc32: 7F746732
md5: 81a57502787fd832d141625494bc6e61
name: 81A57502787FD832D141625494BC6E61.mlw
sha1: 73025e06eb644652e5f43d050663b041f687e53f
sha256: e1c8e34791daee490ba154c10dddf0d43d4cc6910fb08debbd5c722e722ea551
sha512: aecdf00d939762880c15de0f9377d1a3d4dcbe5f9bbd8d272003bfccc38f7314c862c45e0e387ef7d3ac13bb289136f39b32b7869ee22dd1175577d939c0dada
ssdeep: 6144:oUtzB0RzsWEV3SwowlR81T/F19W6fepyq85t:oUZKRzsthSwBRq/5W6fepyb5t
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2018 The OpenSSL Project. Copyright xa9 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.
InternalName: ssleay32
FileVersion: 1.0.121j
CompanyName: The OpenSSL Project, http://www.openssl.org/
Comments: Compiled by Frederik A. Winkelsdorf (opendec.wordpress.com) for the Indy Project (www.indyproject.org)
ProductName: The OpenSSL Toolkit
ProductVersion: 1.0.121j
FileDescription: OpenSSL Shared Library
OriginalFilename: dream.dll
Translation: 0x0409 0x04b0

Win32/Kryptik.HLLQ also known as:

Elasticmalicious (high confidence)
McAfeeTrojan-FTSS!81A57502787F
SangforRiskware.Win32.Wacapew.C
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLLQ
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.46524635
MicroWorld-eScanTrojan.GenericKD.46524635
Ad-AwareTrojan.GenericKD.46524635
ComodoTrojWare.Win32.Agent.zphxw@0
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.46524635
SophosMal/Generic-S (PUA)
AviraTR/AD.UrsnifDropper.qfokv
ArcabitTrojan.Generic.D2C5E8DB
GDataTrojan.GenericKD.46524635
AhnLab-V3Trojan/Win.Generic.C4531900
MAXmalware (ai score=81)
MalwarebytesTrojan.Crypt
IkarusTrojan.Win32.Krypt
FortinetPossibleThreat.MU
AVGWin32:BankerX-gen [Trj]

How to remove Win32/Kryptik.HLLQ?

Win32/Kryptik.HLLQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment