Malware

Win32/Kryptik.HJMG removal tips

Malware Removal

The Win32/Kryptik.HJMG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HJMG virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
finderout.com

How to determine Win32/Kryptik.HJMG?


File Info:

crc32: D81EC1D5
md5: 486a71006c9c1fb20a85823f6a97e611
name: 486A71006C9C1FB20A85823F6A97E611.mlw
sha1: 69e754a620a246e3f2df7ea644acf85abc8993a6
sha256: 057d811888e41fca0d05d8f27f0f761651ff379a207ce67774e5f75253efc236
sha512: e6d067ddf359897a34cb186d0925b5f1489c7d384e7cf4e073b15100ddcca01f5884800eeac6a0471534c994d46afcb51472fcd9fb370ae13ad301d5521a5183
ssdeep: 12288:vOjzytMM46WLkgTRXFZHlbWqfCAZJhacCFl:vOqtMM46skgRXF7PfCA/hacC/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 1.0.0.1
InternalName: HyperLinkDemo.exe
FileVersion: 1.0.0.1
OriginalFilename: HyperLinkDemo.exe
FileDescription: HyperLink Demonstration Executable.
Translation: 0x0409 0x04e4

Win32/Kryptik.HJMG also known as:

DrWebTrojan.DownLoad4.14248
MicroWorld-eScanTrojan.GenericKD.36361204
ALYacTrojan.GenericKD.36361204
SangforBackdoor.Win32.Bazarloader.mt
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36361204
K7GWRiskware ( 0040eff71 )
CyrenW32/Emotet.BBE.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan.Win32.Zenpak.gen
AlibabaBackdoor:Win32/Bazarloader.03d56a23
AegisLabTrojan.Win32.Zenpak.4!c
RisingBackdoor.BazarLoader!8.122C3 (CLOUD)
Ad-AwareTrojan.GenericKD.36361204
SophosMal/Generic-S
ComodoMalware@#e6fgphjzg43s
F-SecureTrojan.TR/AD.Emotet.gie
TrendMicroTROJ_FRS.0NA103BH21
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36361204
EmsisoftMalCert-S.DW (A)
AviraTR/AD.Emotet.gie
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bazarloader
ArcabitTrojan.Generic.D22AD3F4
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataWin32.Trojan.Kryptik.9C590E
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.BazaLoader.R366789
McAfeeArtemis!486A71006C9C
MAXmalware (ai score=87)
VBA32Trojan.Zenpak
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HJMG
TrendMicro-HouseCallTROJ_FRS.0NA103BH21
IkarusTrojan.Emotet
FortinetW32/Kryptik.E611!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.Emotet.HgIASPEA

How to remove Win32/Kryptik.HJMG?

Win32/Kryptik.HJMG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment