Malware

What is “Win32/Kryptik.HGXM”?

Malware Removal

The Win32/Kryptik.HGXM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HGXM virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

support.oracle.com
support.apple.com
loadcessna.asia

How to determine Win32/Kryptik.HGXM?


File Info:

crc32: 23F0A14A
md5: 52e8aeb0c82df0d2d7a1166a252fd0c3
name: upload_file
sha1: 04fe34a62ccbe36b284957cdd7b0e403b4ae725c
sha256: 605d6dbb783fb7ffd54f5f8d9a3cbaf6aa23bbe5c7b384b3c9aa7a23b9b3c150
sha512: d15c41f339349a58b9353019da9d5a3c8cb9216e0473b06144fb035d33ca2854d9ff8b01a0c3cde18aea693266ac5f12ff52dda2858e0490be7b1b0813695402
ssdeep: 3072:AOmOk6enPB2ZkihbIkfPwCwTDMZx1S95p8HQh+Ka2+PBLhA:uP6BaC4CwTDMZx14uICPFhA
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Flower speech Corporation. All rights reserved.
InternalName: Expect SameWrite Teach
FileVersion: 5.3.6.983
CompanyName: Flower speech Corporation
ProductName: Flower speechxae Gentle pastxae
ProductVersion: 5.3.6.983
FileDescription: Flower speech Gentle past
Found: Woman
OriginalFilename: paint.dll
Translation: 0x0409 0x04b0

Win32/Kryptik.HGXM also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44134617
FireEyeTrojan.GenericKD.44134617
ALYacTrojan.IcedID.gen
CylanceUnsafe
AegisLabTrojan.Win32.IcedID.7!c
SangforMalware
K7AntiVirusTrojan ( 005718d41 )
BitDefenderTrojan.GenericKD.44134617
K7GWTrojan ( 005718d41 )
TrendMicroTROJ_GEN.R002C0DJN20
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.IcedID.gen
AlibabaTrojanBanker:Win32/Kryptik.ddb4b619
TencentWin32.Trojan-banker.Icedid.Swuy
Ad-AwareTrojan.GenericKD.44134617
SophosMal/Generic-S
Comodofls.noname@0
F-SecureTrojan.TR/AD.PhotoDlder.vqksm
ZillyaTrojan.Kryptik.Win32.2590172
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.44134617 (B)
JiangminTrojan.Banker.IcedID.qz
WebrootW32.Trojan.Gen
AviraTR/AD.PhotoDlder.vqksm
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Casdet!rfn
ArcabitTrojan.Generic.D2A170D9
ZoneAlarmHEUR:Trojan-Banker.Win32.IcedID.gen
GDataTrojan.GenericKD.44134617
McAfeeGenericRXAA-AA!52E8AEB0C82D
MalwarebytesTrojan.IcedID
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HGXM
TrendMicro-HouseCallTROJ_GEN.R002C0DJN20
RisingTrojan.Generic@ML.89 (RDML:HLnhnmLVIs1gyyPDE6DCJw)
IkarusTrojan.Win32.Krypt
FortinetW32/IcedID.EUSH!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.0f5

How to remove Win32/Kryptik.HGXM?

Win32/Kryptik.HGXM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment