Malware

Win32/Kryptik.HLQL removal

Malware Removal

The Win32/Kryptik.HLQL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLQL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HLQL?


File Info:

crc32: BF027884
md5: 9fb155f63f39c7ffc4376a13f545489f
name: 9FB155F63F39C7FFC4376A13F545489F.mlw
sha1: 4f4bb2955a6acc52b930d0fa1c8ab7141e486293
sha256: ccbe358390ebd7f566b6ed9f6b8afd6a5f2914782605302ea82c33bbeacde2d9
sha512: fa394befc74f34dd261d7af072b5d8fba59081d2a5b25ab7948a9ffdfc9109c454221ed8a8b16c424ce93dc57ead3f29bedfe5a5c223297dfb4dc366f7539c08
ssdeep: 6144:lzEJx1smYyA3NKenKekwZZDwfzK50IKB6R4S63TKo:lzas3NKenKejNsyKBgiT1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04e4

Win32/Kryptik.HLQL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWHacktool ( 700007861 )
Cybereasonmalicious.55a6ac
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLQL
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderTrojan.GenericKD.37207409
MicroWorld-eScanTrojan.GenericKD.37207409
Ad-AwareTrojan.GenericKD.37207409
SophosMal/Generic-R + Troj/Kryptik-TR
BitDefenderThetaGen:NN.ZexaF.34790.tuW@a8IlB@jG
McAfee-GW-EditionBehavesLike.Win32.Emotet.fh
FireEyeGeneric.mg.9fb155f63f39c7ff
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Packed.Kryptik.8MCVLZ
AhnLab-V3Trojan/Win.PWSX-gen.C4545398
Acronissuspicious
McAfeeArtemis!9FB155F63F39
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:MalwareX-gen [Trj]
Qihoo-360HEUR/QVM10.1.739F.Malware.Gen

How to remove Win32/Kryptik.HLQL?

Win32/Kryptik.HLQL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment