Malware

Win32/Kryptik.HLMR (file analysis)

Malware Removal

The Win32/Kryptik.HLMR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLMR virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
sergeevih43.tumblr.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Win32/Kryptik.HLMR?


File Info:

crc32: 01B0E7B4
md5: adaa653ea596841f6ee156da11f9c878
name: ADAA653EA596841F6EE156DA11F9C878.mlw
sha1: b05b2a867c086b6841eae23e684407ff4ece3232
sha256: 71407dd4cf7787d2529b435a8e24e0899b0b2e5ab0482abcd507ecd862358923
sha512: 9f06ae2273c6b3221f6b4d1cbf2a830c1debfc30178862b7e6ab2ee93dbdf9cd8f784aa14fe7b0ec92e3c3519e63bac6ba59148f263d83515a110a57a2ab8957
ssdeep: 12288:oc50IrE11naiBrn01Oy6s6TBseUS7STLy3IfpfI1+kjOo3xM7:h0IA11JIwy6NseUS7S3yOKx3xM7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x48e6 0x035b

Win32/Kryptik.HLMR also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader40.1895
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37144659
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Glupteba.1bb7abe9
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.QTUA-9033
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLMR
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKD.37144659
MicroWorld-eScanTrojan.GenericKD.37144659
Ad-AwareTrojan.GenericKD.37144659
SophosMal/Generic-R + Troj/Kryptik-TR
BitDefenderThetaGen:NN.ZexaF.34758.QuW@aS4kGzpO
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.STOP.SMYXBFX.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.adaa653ea596841f
EmsisoftTrojan.GenericKD.37144659 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Racealer.cln
WebrootW32.Chapak
eGambitUnsafe.AI_Score_75%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.QS!MTB
GridinsoftTrojan.Win32.Packed.lu!heur
ArcabitTrojan.Generic.D236C853
AegisLabTrojan.Win32.Pycoon.i!c
ZoneAlarmHEUR:Trojan.Win32.Chapak.gen
GDataTrojan.GenericKD.37144659
AhnLab-V3Trojan/Win.Azorult.R427593
Acronissuspicious
McAfeePacked-GDT!ADAA653EA596
MAXmalware (ai score=80)
VBA32BScope.Trojan.Crypt
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H07FO21
RisingTrojan.Kryptik!1.D792 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.TR!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HLMR?

Win32/Kryptik.HLMR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment