Malware

Win32/Kryptik.HMFX malicious file

Malware Removal

The Win32/Kryptik.HMFX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMFX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HMFX?


File Info:

crc32: 87730FC9
md5: 5b0e056cc4170183afafb9bd8c2e7764
name: 5B0E056CC4170183AFAFB9BD8C2E7764.mlw
sha1: 6e6ff3f39fda1d6505c1831cc846b7dcbf405efa
sha256: 27caeabbbc3f50ddde02957ab8b5e196077f534e522c7be75b32fc369d2ac282
sha512: d8414917356d269354ebbf6e7b4ea7537f033f399da5952a03116f5d5e6523cf0061d1ef871552a63caf7705c0eb4ae60c4b779dbdece024658ac32aa5c09cab
ssdeep: 6144:BSRHG1dtQdoDRvTr9O/5sHfKzmPtZBW1HwhZU9sI5/:BSg1dthRnARq1Kec
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloku.aci
ProductVersion: 7.59.25.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0183 0x022e

Win32/Kryptik.HMFX also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056f9be1 )
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.2532
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37485979
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Application/Obfuscated.ec0d768c
K7GWTrojan ( 005690681 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMFX
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Generic-9888554-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.37485979
MicroWorld-eScanTrojan.GenericKD.37485979
Ad-AwareTrojan.GenericKD.37485979
SophosML/PE-A + Troj/Krypt-BO
ComodoTrojWare.Win32.UMal.kyana@0
BitDefenderThetaGen:NN.ZexaF.34110.rq0@aCpznIkG
TrendMicroMal_HPGen-50
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.5b0e056cc4170183
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.oflrj
eGambitUnsafe.AI_Score_86%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftTrojan.Win32.Packed.lu!heur
ArcabitTrojan.Fragtor.D2F13
GDataWin32.Packed.Kryptik.1X65AS
AhnLab-V3Infostealer/Win.SmokeLoader.R439016
Acronissuspicious
McAfeePacked-GDT!5B0E056CC417
MAXmalware (ai score=81)
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Kryptik!1.D8AC (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KRYPT.BO!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/Kryptik.HMFX?

Win32/Kryptik.HMFX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment