Trojan

Trojan:Win32/Hynamer.A!ml removal tips

Malware Removal

The Trojan:Win32/Hynamer.A!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Hynamer.A!ml virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Finnish
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.org
apps.identrust.com
rrrrload08.top

How to determine Trojan:Win32/Hynamer.A!ml?


File Info:

crc32: A7BD3719
md5: a15ae46f00f2cde9546259ce71751800
name: infostat.exe
sha1: cfa4e7a75000d4b182e9fb81896819016d6932bd
sha256: ba1fbd2219f58e87e7df204b6dfa588417fe651a3b35f6735835b51d087cd663
sha512: 09bd2335bf11a61c886a5d33eaa6f9d4d905a9e6e8beb54531d378337eced3dea592660a3f5d26f2514a980f3c20588b6c88b628d0775fb6959ab9ed7c4b7ee2
ssdeep: 12288:iBwzwBFcXlHY5cibxoAzFUWHUVyhAuNDSyxy25S5:1w8dYeiegFUW0QXN425S5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0491 0x0315

Trojan:Win32/Hynamer.A!ml also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKDZ.68198
FireEyeGeneric.mg.a15ae46f00f2cde9
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056809d1 )
BitDefenderTrojan.GenericKDZ.68198
K7GWTrojan ( 00564bda1 )
Cybereasonmalicious.75000d
TrendMicroTROJ_GEN.R049C0WFR20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Bunitu-8273607-0
GDataTrojan.GenericKDZ.68198
KasperskyTrojan.Win32.Chapak.enyo
AlibabaTrojan:Win32/Kryptik.c791a6eb
AegisLabTrojan.Win32.Malicious.4!c
RisingMalware.Heuristic!ET#97% (RDMK:cmRtazqn984cUAVNwju4yrJZ/0xN)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.AHKInfoSteal.ybjxh
Invinceaheuristic
EmsisoftTrojan.GenericKDZ.68198 (B)
SentinelOneDFI – Malicious PE
AviraTR/AD.AHKInfoSteal.ybjxh
ArcabitTrojan.Generic.D10A66
ZoneAlarmTrojan.Win32.Chapak.enyo
MicrosoftTrojan:Win32/Hynamer.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R341698
Acronissuspicious
ALYacTrojan.GenericKDZ.68198
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKDZ.68198
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HELF
TrendMicro-HouseCallTROJ_GEN.R049C0WFR20
IkarusTrojan.Win32.Crypt
FortinetPossibleThreat.MU
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM10.1.328F.Malware.Gen

How to remove Trojan:Win32/Hynamer.A!ml?

Trojan:Win32/Hynamer.A!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment