Malware

Win32/Kryptik.HLNV removal

Malware Removal

The Win32/Kryptik.HLNV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLNV virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Looks up the external IP address

Related domains:

api.ipify.org
158.102.105.176.zen.spamhaus.org
158.102.105.176.cbl.abuseat.org
158.102.105.176.b.barracudacentral.org
158.102.105.176.dnsbl-1.uceprotect.net
158.102.105.176.spam.dnsbl.sorbs.net

How to determine Win32/Kryptik.HLNV?


File Info:

crc32: 367DCB48
md5: 6daccc54cd517e02c320ff14461ae729
name: 6DACCC54CD517E02C320FF14461AE729.mlw
sha1: d6997e1f95b31701a75a2082528f23ec34b47003
sha256: 8368a955dd5d9850ed8ced6144a202368c52e065abafdb71a7960d3a90647e85
sha512: f6940556982687110d64ecc6acfa20e89d929a896d4b7e2b974011db02b9a3aa18f6145425cace9690d7d859ee4f2b7f808ea8518a84d76a2050c7218ea28594
ssdeep: 49152:bX85+GzBYx5ulXJyA889lRN2G6tEw1um7WHgKLES5fQC4NIINE67Qg3ErgbJwaT1:/ISulgA889lRN2G6mwggUrgbJyaBR
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HLNV also known as:

ALYacTrojan.Trickster.Gen
CylanceUnsafe
SangforTrojan.Win32.Trickpak.ky
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0057eb3c1 )
K7AntiVirusTrojan ( 0057eb3c1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLNV
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Trickpak.ga
BitDefenderTrojan.GenericKD.46550449
MicroWorld-eScanTrojan.GenericKD.46550449
Ad-AwareTrojan.GenericKD.46550449
SophosMal/Generic-S
ComodoMalware@#11t019v2j0hz7
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103FU21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.6daccc54cd517e02
EmsisoftTrojan.GenericKD.46550449 (B)
AviraTR/Crypt.Agent.aeghk
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/TrickBot.Z!ibt
ArcabitTrojan.Generic.D2C64DB1
AegisLabTrojan.Win32.Trickster.7!c
GDataTrojan.GenericKD.46550449
AhnLab-V3Trojan/Win.Trickbot.C4538130
McAfeeGenericRXAA-AA!6DACCC54CD51
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103FU21
IkarusTrojan-Spy.Win32.TrickBot
FortinetW32/PossibleThreat
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.Hx4CPJsA

How to remove Win32/Kryptik.HLNV?

Win32/Kryptik.HLNV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment