Malware

About “Win32/Kryptik.HMFP” infection

Malware Removal

The Win32/Kryptik.HMFP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMFP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HMFP?


File Info:

crc32: 8921364C
md5: 84d4f42700e25257dd5180c30af9daec
name: 84D4F42700E25257DD5180C30AF9DAEC.mlw
sha1: a26c5c37dc3d3de761b9a139a79f2d97c76ca5a8
sha256: 95fdda1da7a2172ac7b2c0e4cf0fa1e40faf2990a46f132597271754a721300c
sha512: 05e068b6c1e2bd309198495b3f68e029f5bd8dc0e6ffd1c8c8bd53374f32d173c23ffd3b52b4bd2c6d81945c8ca9c64018258deb79ace75988b3cbfb4199576c
ssdeep: 6144:JA2yTosGRkYHt55am5ABJFZBjeHAHwhZU9sI5/:JqojKYHt5rCnBjWAec
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloku.aci
ProductVersion: 7.59.25.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0183 0x022e

Win32/Kryptik.HMFP also known as:

K7AntiVirusTrojan ( 0056f9be1 )
Elasticmalicious (high confidence)
ClamAVWin.Packed.Generic-9888553-0
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0056f9be1 )
Cybereasonmalicious.7dc3d3
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMFP
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Spy.Win32.Stealer.gen
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34104.rq0@aaTpR7gG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.84d4f42700e25257
EmsisoftTrojan.Crypt (A)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.FW!MTB
GridinsoftRansom.Win32.STOP.ko!se1076
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.PSE.1PQMODY
AhnLab-V3Infostealer/Win.SmokeLoader.R438930
Acronissuspicious
McAfeePacked-GDT!84D4F42700E2
MAXmalware (ai score=99)
VBA32BScope.TrojanRansom.Blocker
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
IkarusWin32.Outbreak
FortinetW32/GenKryptik.FJNZ!tr
AVGFileRepMalware

How to remove Win32/Kryptik.HMFP?

Win32/Kryptik.HMFP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment