Malware

About “Win32/Kryptik.HMID” infection

Malware Removal

The Win32/Kryptik.HMID is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMID virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com

How to determine Win32/Kryptik.HMID?


File Info:

crc32: 3FE5B853
md5: f3e45f00b14b27a28c0ac04b5475a4a3
name: F3E45F00B14B27A28C0AC04B5475A4A3.mlw
sha1: e32d9e41ca35311d8593475ee005c3ceecfd3bb9
sha256: 2457694ff7a2d4ec5881b14863764a2aea6f16e41daec0998ca45c53f435d8b3
sha512: bec4cc9cd317fbe00aa1af60ea0770711b34ce870e0081013575c519801238fde37e1fa241aa23d3a827971de9c3373fcb779364021f048066d8dffea77d658b
ssdeep: 6144:WVCLRdtlV/6gpDylvxV9Oscokw70Ab/tqwkTw7t31/+010b40k3GZ5dWOmtMGd7:WVCbd/6227vPcor7dMTuiG5lCxa7T
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: saxzmoimoku.apa
ProductVersion: 7.12.29.13
Copyright: Copyrighz (C) 2021, fudkagata
Translation: 0x0121 0x009f

Win32/Kryptik.HMID also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056d16b1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader42.1632
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Azorult.c8e57933
K7GWTrojan ( 0056d16b1 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HMID
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderTrojan.GenericKD.37528056
MicroWorld-eScanTrojan.GenericKD.37528056
TencentWin32.Trojan.Zenpak.Eequ
Ad-AwareTrojan.GenericKD.37528056
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34126.Dq0@aKxgx8aG
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.f3e45f00b14b27a2
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.RF!MTB
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.GenericKD.37528056
AhnLab-V3CoinMiner/Win.Glupteba.R440044
Acronissuspicious
McAfeeRDN/Generic.dx
MAXmalware (ai score=86)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D91D (CLASSIC)
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMIM!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HMID?

Win32/Kryptik.HMID removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment