Malware

About “Win32/Kryptik.HLZC” infection

Malware Removal

The Win32/Kryptik.HLZC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLZC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HLZC?


File Info:

crc32: A8F32B86
md5: 9e593c132c5c1a5e36b545daf3137aca
name: 9E593C132C5C1A5E36B545DAF3137ACA.mlw
sha1: e4f5a8e3f6a484235380f469435287445eb0fd8c
sha256: 4cd43ae99f4a8ca39cd1659b37d14b8bbe60e26fb629c2d59b39255c013c7680
sha512: ead78a54c98c327cf14274bec4e408250dfedfd4ded62cba975ea0fbb6949997ef22c97ffbc27caba2a844d041cf177ec04bca59fabdb9e8fd48dbfaf11d6379
ssdeep: 3072:2ZfdZcaNL3/DyL0Ccm/QDYGd5CnDkGD0Lb8zxJWtk02syVUI:i3NNL3/DyZN5nPpxJgLBI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: kogzmuadeke.exi
ProductVersion: 91.78.38.18
Copyright: Copyrighz (C) 2020, vodkagats
Translation: 0x0182 0x0101

Win32/Kryptik.HLZC also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.DownLoader41.2861
CynetMalicious (score: 100)
ALYacGen:Heur.Mint.Titirez.mm0@@mCeoUj
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.3f6a48
CyrenW32/Banker.HC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLZC
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Dropper.Ursnif-9884016-0
KasperskyUDS:Trojan.Win32.Chapak
BitDefenderGen:Heur.Mint.Titirez.mm0@@mCeoUj
MicroWorld-eScanGen:Heur.Mint.Titirez.mm0@@mCeoUj
Ad-AwareGen:Heur.Mint.Titirez.mm0@@mCeoUj
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.9e593c132c5c1a5e
EmsisoftGen:Heur.Mint.Titirez.mm0@@mCeoUj (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.jkygv
MicrosoftTrojan:Win32/Caynamer.A!ml
GridinsoftRansom.Win32.STOP.ko!se63951
GDataGen:Heur.Mint.Titirez.mm0@@mCeoUj
AhnLab-V3Malware/Win.Generic.C4582277
Acronissuspicious
McAfeeArtemis!9E593C132C5C
MAXmalware (ai score=80)
VBA32BScope.Trojan.Caynamer
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Kryptik!1.D82C (CLASSIC)
IkarusTrojan-Banker.UrSnif
FortinetW32/UrSnif.C6C8!tr
AVGWin32:MalwareX-gen [Trj]
Qihoo-360HEUR/QVM10.1.1576.Malware.Gen

How to remove Win32/Kryptik.HLZC?

Win32/Kryptik.HLZC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment