Malware

Win32/Kryptik.HMFH removal guide

Malware Removal

The Win32/Kryptik.HMFH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMFH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Kazak
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
4kcontent.xyz
iplogger.org
api.ip.sb
freegeoip.app
youtube4kdowloader.club

How to determine Win32/Kryptik.HMFH?


File Info:

crc32: 44CA1F8D
md5: 03fd31222d4b73f3c8a62ac31d928596
name: 03FD31222D4B73F3C8A62AC31D928596.mlw
sha1: fa3332722b6ba54b4945743e62a9fcc21aad8a2d
sha256: 47e0d99ecad391a79c496c5cb42d6576c24642bd9bfa12fa59ab946277d26a10
sha512: 9f13e3f5e8e066146392011946908f4b377a20bb61b18313a3c24c6053ee82613049db75f4d5f03631821d83d7d04851257726a91361d25d4b061633c1ff126e
ssdeep: 6144:s5eS4PYivjHJIAlgBmGDgCDHpzb9k5GORkfUW0VOSbljzF/2GxYpuE/3:PSeYiLpIGFGDgCDBb7mkfRSbj20YAM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x120a 0x052e

Win32/Kryptik.HMFH also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.64457
CAT-QuickHealRansom.Stop.Z5
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Fragtor.11605
Cybereasonmalicious.22b6ba
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMFH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
MicroWorld-eScanGen:Variant.Fragtor.11605
Ad-AwareGen:Variant.Fragtor.11605
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34104.xqW@aaHKbvbG
TrendMicroTROJ_GEN.R06CC0DHP21
McAfee-GW-EditionBehavesLike.Win32.Trojan.fc
FireEyeGeneric.mg.03fd31222d4b73f3
EmsisoftGen:Variant.Fragtor.11605 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.RT!MTB
ZoneAlarmHEUR:Trojan-Ransom.Win32.Stop.gen
GDataWin32.Trojan-Spy.BeamLoader.9B6D2Y
AhnLab-V3CoinMiner/Win.Glupteba.R438825
Acronissuspicious
McAfeeArtemis!03FD31222D4B
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R06CC0DHP21
RisingTrojan.Kryptik!1.C6FC (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Kryptik.HMFH?

Win32/Kryptik.HMFH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment