Malware

Win32/Kryptik.HMCU removal tips

Malware Removal

The Win32/Kryptik.HMCU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMCU virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Algeria)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HMCU?


File Info:

crc32: 419B5532
md5: 46b2b8e7621a93ae6b876b071da55212
name: 46B2B8E7621A93AE6B876B071DA55212.mlw
sha1: 5bee5a91e0eb6c3c90c80a773226724f68149658
sha256: 9da4d8126ac0c4c0b68066407e24cf1a36e06f0fc22ef87b0a464f90c1374095
sha512: ad5740f00355c9d38a1fa816d4aa03826d23c5cc3155e3b24b0d900550bfc8ecced52f26c4dbf75f70a6f87aae7edec7dd0a09763e418f89cd23e49138c68e49
ssdeep: 6144:0zAfLQsyTvBg96hLshzuKd4lNC0wxkBl0:3LITa6SJuwaB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmeoleke.ewi
ProductVersion: 7.21.22.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0182 0x003a

Win32/Kryptik.HMCU also known as:

K7AntiVirusTrojan ( 0056f9be1 )
LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Generic-9886591-0
McAfeePacked-GDT!46B2B8E7621A
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 0056f9be1 )
Cybereasonmalicious.1e0eb6
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMCU
APEXMalicious
AvastFileRepMetagen [Malware]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Blocker.gen
BitDefenderTrojan.GenericKD.46813067
MicroWorld-eScanTrojan.GenericKD.46813067
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.46813067
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34088.sq1@amDvdhpG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.46b2b8e7621a93ae
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_71%
MicrosoftRansom:Win32/StopCrypt.MPK!MTB
GridinsoftRansom.Win32.STOP.ko!se37341
ArcabitTrojan.Generic.D2CA4F8B
GDataTrojan.GenericKD.46813067
AhnLab-V3CoinMiner/Win.Glupteba.R437681
Acronissuspicious
VBA32BScope.TrojanRansom.Blocker
MAXmalware (ai score=86)
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D82C (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FJBW!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwoCUugA

How to remove Win32/Kryptik.HMCU?

Win32/Kryptik.HMCU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment