Malware

Win32/Kryptik.HJNM removal tips

Malware Removal

The Win32/Kryptik.HJNM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HJNM virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Collects information about installed applications

How to determine Win32/Kryptik.HJNM?


File Info:

crc32: 05713C02
md5: 4ee129a17d4714d96f9a56e5f5aeb49f
name: 4EE129A17D4714D96F9A56E5F5AEB49F.mlw
sha1: 49d6323987c01c2b887101ff493b510229e17428
sha256: 120c3c37af1672c02ce61d7a64795e9cf44146a6e753e5d889c3bfa360d6cd2d
sha512: f0c845e941b7af77db60447c4e04a0a693e5327f58baff19fa9da2fcc28eecf18743c000d36eca32ba82bdf6dbd620e6517c064023fcb11fe48f9a88e8f9be79
ssdeep: 12288:kbqkjZS1Vu8MpJYosZUmc16RWdrpo8+FFcLxT8HoxmRsDJteMKTy81MOU7qOkQR:kbqkjZSqxYjxoArwQobmMKpiOUFkK1
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2019 VMware, Inc.
InternalName: vmwarecui
FileVersion: 15.8.2 build-223
CompanyName: VMware, Inc.
ProductName: VMware Workstation
ProductVersion: 15.8.2 build-223
FileDescription: VMware cui library
OriginalFilename: heart.dll
Translation: 0x0419 0x04e3

Win32/Kryptik.HJNM also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36367064
McAfeeRDN/Dridex
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Kryptik.adcd41ab
K7GWTrojan ( 005780bb1 )
K7AntiVirusTrojan ( 005780bb1 )
ArcabitTrojan.Cerbu.D163FA
CyrenW32/Trojan.GTAA-3309
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HJNM
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.Cridex.gen
BitDefenderTrojan.GenericKD.36367064
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareTrojan.GenericKD.36367064
EmsisoftTrojan.GenericKD.36367064 (B)
F-SecureTrojan.TR/AD.Dridex.umvme
DrWebTrojan.Siggen12.833
TrendMicroTROJ_FRS.VSNTBI21
SophosMal/Generic-S
AviraTR/AD.Dridex.umvme
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.Cridex.gen
GDataTrojan.GenericKD.36367064
CynetMalicious (score: 100)
MAXmalware (ai score=85)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSNTBI21
IkarusTrojan-Spy.Win32.Tepfer
FortinetPossibleThreat.MU
AVGWin32:MalwareX-gen [Trj]
AvastWin32:MalwareX-gen [Trj]

How to remove Win32/Kryptik.HJNM?

Win32/Kryptik.HJNM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment