Malware

Win32/Kryptik.HMIU malicious file

Malware Removal

The Win32/Kryptik.HMIU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMIU virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Collects information about installed applications
  • Attempts to modify proxy settings

How to determine Win32/Kryptik.HMIU?


File Info:

crc32: F1978813
md5: 1f1da846719f443bdc99fe6d21ba04d7
name: 1F1DA846719F443BDC99FE6D21BA04D7.mlw
sha1: c9cc808181171b2c51d23769f2e8bb3eb038b0e2
sha256: c6772905c4d1c6509a898d76957a9561d97509f72f6c91bdfe0a183464e86a8d
sha512: 2a38a97323cbcaa837c5bb87ffa231a6af08642822c02c716fb0af14a302e4693d67bb3687603e5ef517a8135397487f8f616309727b7e5cb7cb51a9267ce918
ssdeep: 24576:uMcpTo6ewNHvbyVfbWWbyHjaSabybbybvkbleb:uMuT5Ek
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Slacker, Inc. 2006-2010.
InternalName: jukebox
FileVersion: 2.1.2370.0000
CompanyName: Slacker
ProductName: Slacker Software Player
ProductVersion: 2.1.2370.0000
FileDescription: Slacker Jukebox
OriginalFilename: slacker.jukebox.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.HMIU also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00581e191 )
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.735
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.918693
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00581e191 )
CyrenW32/Kryptik.FDU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMIU
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan.Win32.Qshell.jiq
BitDefenderGen:Variant.Razy.918693
MicroWorld-eScanGen:Variant.Razy.918693
Ad-AwareGen:Variant.Razy.918693
SophosML/PE-A + Mal/EncPk-APV
BitDefenderThetaGen:NN.ZexaF.34142.fv0@auhLyXai
McAfee-GW-EditionBehavesLike.Win32.Dropper.tz
FireEyeGeneric.mg.1f1da846719f443b
EmsisoftGen:Variant.Razy.918693 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Dridex.jnlny
Antiy-AVLTrojan/Generic.ASMalwS.3319637
MicrosoftTrojan:Script/Phonzy.C!ml
GDataGen:Variant.Razy.918693
AhnLab-V3Trojan/Win.Qshell.R440726
Acronissuspicious
McAfeeGenericRXAA-AA!1F1DA846719F
MAXmalware (ai score=86)
VBA32BScope.Virus.Virlock
MalwarebytesMalware.AI.3911150552
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.D606 (CLASSIC)
FortinetW32/Qshell.FO!tr
AVGWin32:BankerX-gen [Trj]

How to remove Win32/Kryptik.HMIU?

Win32/Kryptik.HMIU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment