Malware

Win32/Kryptik.HMDY removal

Malware Removal

The Win32/Kryptik.HMDY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMDY virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Norwegian (Bokmal)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HMDY?


File Info:

crc32: B211F610
md5: 9170f26f689ad9b18ca8363031a490cc
name: 9170F26F689AD9B18CA8363031A490CC.mlw
sha1: 671b67c0b1b9ecd770297f872aafd76dec5df5a7
sha256: 7c0a44319ba7a567058b139432f5a549f937d2c9e499006744beffc927c8ce6a
sha512: 6e1bf28ad1b9de301638261c184b985a13cca9e2dbd5c489a661fd9a5d8286f0ff8d324dd4adf53a8daa9f348344e302fd0ee44e6943880fe7f6ad1d0201219e
ssdeep: 1536:h3DyjIOeetL7EhTkPjGHn62TTcUS0ulEoB/f3T9lx/6r43jmxTgWUXdLdN:12aoL7mQjGHn6QYVRB/hv/ukmuWedLdN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0414 0x04b0
InternalName: PARAXONMA
FileVersion: 1.00
CompanyName: Common Class
Comments: Common Class
ProductName: Common Class
ProductVersion: 1.00
FileDescription: Common Class
OriginalFilename: PARAXONMA.exe

Win32/Kryptik.HMDY also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37440617
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Kryptik.FAV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMDY
APEXMalicious
AvastWin32:DangerousSig [Trj]
ClamAVWin.Malware.Generic-9887177-0
KasperskyTrojan.Win32.Mucc.qju
BitDefenderTrojan.GenericKD.37440617
MicroWorld-eScanTrojan.GenericKD.37440617
Ad-AwareTrojan.GenericKD.37440617
SophosMal/Generic-S
Comodofls.noname@0
BitDefenderThetaGen:NN.ZevbaF.34088.im1@aGcxNiaO
FireEyeGeneric.mg.9170f26f689ad9b1
EmsisoftTrojan.GenericKD.37440617 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.pjyoq
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Script/Phonzy.C!ml
GDataTrojan.GenericKD.37440617
AhnLab-V3Trojan/Win.Guloader.R438317
McAfeeGenericRXPT-KF!9170F26F689A
MAXmalware (ai score=89)
MalwarebytesTrojan.GuLoader
PandaTrj/GdSda.A
YandexTrojan.Igent.bWqXGH.6
IkarusTrojan.VB.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EPYN!tr
AVGWin32:DangerousSig [Trj]

How to remove Win32/Kryptik.HMDY?

Win32/Kryptik.HMDY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment