Malware

Win32/Kryptik.HLWK malicious file

Malware Removal

The Win32/Kryptik.HLWK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLWK virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Telugu
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Win32/Kryptik.HLWK?


File Info:

crc32: 212E741F
md5: 707e2e40d4a958d1a2612dd11a442e2e
name: 707E2E40D4A958D1A2612DD11A442E2E.mlw
sha1: 0c796bb7eefb29ea4fd24d33dd0c17faf6d2c347
sha256: 1d7c32fbb0d4f6fa794e0dfd1e50396e0e90d5a6d776110037084908c721a835
sha512: ce67aa7654e6a63dd23b442cd384b76ba26d7892c82c1d71efe1699b8f41e84ecc3edfb55d30f8e71c0c2163c9ae290e7c4206703726ed2f3b418cda904b8f22
ssdeep: 12288:0pwzFbiCKvviwnbt3+lnIbhV5rCgAQ00mbZUo71juz2ceauX+:0yFbignI1DCOnNz2cehu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x020a 0x054b

Win32/Kryptik.HLWK also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.47304
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.76692
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.7eefb2
CyrenW32/Kryptik.ESK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLWK
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Malware.Generic-9881904-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKDZ.76692
MicroWorld-eScanTrojan.GenericKDZ.76692
Ad-AwareTrojan.GenericKDZ.76692
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34050.FuW@aif7OehG
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.707e2e40d4a958d1
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
MicrosoftRansom:Win32/StopCrypt.MVK!MTB
ArcabitTrojan.Generic.D12B94
GDataTrojan.GenericKDZ.76692
AhnLab-V3Trojan/Win.PWSX-gen.C4571022
Acronissuspicious
McAfeePacked-GDT!707E2E40D4A9
MAXmalware (ai score=88)
VBA32BScope.Trojan.Crypt
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.C6FC (CLASSIC)
IkarusTrojan.Win32.Glupteba
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HLWQ!tr
AVGWin32:PWSX-gen [Trj]
Qihoo-360HEUR/QVM10.1.00C7.Malware.Gen

How to remove Win32/Kryptik.HLWK?

Win32/Kryptik.HLWK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment