Malware

What is “Win32/Kryptik.HDMO”?

Malware Removal

The Win32/Kryptik.HDMO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HDMO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to stop active services
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Clears Windows events or logs
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HDMO?


File Info:

crc32: 128E7BB5
md5: 4673b7ac225fbe4e03a55cf7afa2c05a
name: rundll32.exe
sha1: a89acaed1ab67c51d6128cc786f03569c032978e
sha256: 309c0618d48191791561a13625ab8843bc32c92e25c2f20454c2c4c8121827c0
sha512: a745810844adeee23f426d6398d5afc970bb3c38299810e8828573901ed8ee5e7bb69b992a2c15400f38a7c63ab9de4367cc4bb343f87e8a9b8022fc247464de
ssdeep: 3072:FtkZLrfCbBZyILWOUtThruseejRtx2nJN2RLFhtpEw:qLrfCFZhartTEseyx26RLFhA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2020, jlfvjs
InternalName: dvezejzaz.em
FileVersion: 1.4.23.4
Translation: 0x0811 0x0528

Win32/Kryptik.HDMO also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.43195471
McAfeePacked-GBE!4673B7AC225F
CylanceUnsafe
AegisLabTrojan.Win32.Blocker.j!c
SangforMalware
K7AntiVirusTrojan ( 005662121 )
BitDefenderTrojan.GenericKD.43195471
K7GWTrojan ( 005662121 )
Cybereasonmalicious.d1ab67
ArcabitTrojan.Generic.D2931C4F
Invinceaheuristic
CyrenW32/Ulise.BI.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HDMO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Blocker.moaw
AlibabaTrojan:Win32/Blocker.057bf3d0
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Kryptik!1.C46C (CLOUD)
Ad-AwareTrojan.GenericKD.43195471
EmsisoftTrojan.GenericKD.43195471 (B)
F-SecureTrojan.TR/AD.PhobosRansom.bczip
DrWebTrojan.MulDrop12.25853
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FortinetW32/GandCrab.G!tr
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.4673b7ac225fbe4e
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
F-ProtW32/Ulise.BI.gen!Eldorado
AviraTR/AD.PhobosRansom.bczip
MAXmalware (ai score=99)
Antiy-AVLTrojan[Ransom]/Win32.Blocker
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/MultiPlug.PVE!MTB
ZoneAlarmTrojan-Ransom.Win32.Blocker.moaw
AhnLab-V3Trojan/Win32.MalPe.R337071
Acronissuspicious
ALYacTrojan.GenericKD.43195471
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.MalPack.GS
TencentWin32.Trojan.Blocker.Pcsp
IkarusTrojan-Dropper.Agent
GDataTrojan.GenericKD.43195471
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/HEUR/QVM10.2.5C1C.Malware.Gen

How to remove Win32/Kryptik.HDMO?

Win32/Kryptik.HDMO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment