Malware

About “Win32/Kryptik.HFML” infection

Malware Removal

The Win32/Kryptik.HFML is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFML virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Georgian
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

tldrnet.top
redirector.gvt1.com
r4—sn-4g5ednsy.gvt1.com

How to determine Win32/Kryptik.HFML?


File Info:

crc32: A79442BB
md5: 1c40912807f088e49290eb13e615aef6
name: xmr.exe
sha1: a236bd79a94a91b4e9f3e98b8baf150ae2d43908
sha256: 484887f9a4250d012b94800bcfb364cdc8f3d809d5d0e47f64a6f3c4e7a352a5
sha512: 61a29e6d2e9182edafba48998241b2d174a02ac4878353481481cff623dc59530e69b546fbde9280108fe05f1c3146a051dcaf670421ba87e8116de9d1c675c9
ssdeep: 49152:BOTuN/CWOgvjnIaWXy8rsp0scG1ZjyOTgETb06N4HS43wmMT6rv:BOtWf1WXxsOscGfyZE/0vHS43wmu8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: staxfrok.uda
FileV: 1.2.9

Win32/Kryptik.HFML also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34347936
ALYacTrojan.GenericKD.43652713
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
BitDefenderTrojan.GenericKD.34347936
K7GWHacktool ( 700007861 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D20C1BA0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HFML
TrendMicro-HouseCallTROJ_GEN.R002C0WHD20
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Autit.omc
TencentWin32.Trojan-dropper.Autit.Dzae
Ad-AwareTrojan.GenericKD.34347936
EmsisoftTrojan.GenericKD.34347936 (B)
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/AD.CoinMiner.X
Invinceaheuristic
SentinelOneDFI – Malicious PE
FireEyeGeneric.mg.1c40912807f088e4
SophosMal/Generic-S
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.CoinMiner.X
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Caynamer.A!ml
ZoneAlarmTrojan-Dropper.Win32.Autit.omc
GDataTrojan.GenericKD.34347936
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4179903
Acronissuspicious
McAfeeArtemis!1C40912807F0
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusTrojan.Bulta
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.EQGA!tr
WebrootW32.Trojan.Gen
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]
Qihoo-360Win32/Trojan.Dropper.376

How to remove Win32/Kryptik.HFML?

Win32/Kryptik.HFML removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment