Malware

Win32/Kryptik.HLZO information

Malware Removal

The Win32/Kryptik.HLZO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HLZO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HLZO?


File Info:

crc32: 4F717F99
md5: ff50cf6d8276b8d5725cd8a92783eee3
name: FF50CF6D8276B8D5725CD8A92783EEE3.mlw
sha1: ed868cf9c5099b011f2df68bed662717cd4ba556
sha256: 6d0f357a9ee8116e099fd300badb8a437018208f60a53fb1a675a16722cfe20d
sha512: fa0f1a5f78c61acf6c9a466e5a6e4ecbd5ca3c5c4d436198063b5073e3f14f21a73fcad8226596eb5d42782f6b2e37e393f4fe398bc8142a796a7fb64689508f
ssdeep: 98304:w8II6i5xjM8keJpUa+CKgSVWaI4qcWdmzzuG/4c81:/L5xjM8VjKCXSKrdCG1
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2018 Ariolic Software, Ltd.
InternalName: ActiveSMART DLL
FileVersion: 2.10.2.167
CompanyName: Ariolic Software (http://www.ariolic.com)
SpecialBuild: UNICODE
Comments: ab28886af3b6f732ef902aaf66703c121f6899eb
ProductName: Active SMART
ProductVersion: 2.10.2.167
FileDescription: ActiveSMART Library
OriginalFilename: ActiveSMART.exe
Translation: 0x0000 0x04b0

Win32/Kryptik.HLZO also known as:

K7AntiVirusTrojan ( 00580bdb1 )
Elasticmalicious (high confidence)
ALYacTrojan.GenericKDZ.79431
MalwarebytesAdware.DownloadAssistant
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 00580bdb1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLZO
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Adload.thhs
BitDefenderTrojan.GenericKDZ.79431
MicroWorld-eScanTrojan.GenericKDZ.79431
Ad-AwareTrojan.GenericKDZ.79431
SophosTroj/Agent-BHKP
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
FireEyeGeneric.mg.ff50cf6d8276b8d5
EmsisoftTrojan.GenericKDZ.79431 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.Agent.gwukw
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.FOM1ZH
AhnLab-V3Trojan/Win.Generic.R447909
McAfeeArtemis!FF50CF6D8276
MAXmalware (ai score=82)
VBA32BScope.TrojanDownloader.Adload
PandaGeneric Suspicious
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/Kryptik
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HLZO?

Win32/Kryptik.HLZO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment