Malware

Win32/Kryptik.HMOY (file analysis)

Malware Removal

The Win32/Kryptik.HMOY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMOY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Traditional)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Win32/Kryptik.HMOY?


File Info:

crc32: B6759263
md5: 83c12d2c11d79a56cf541d34ebcc17df
name: 83C12D2C11D79A56CF541D34EBCC17DF.mlw
sha1: 04f73a82fba11a1f3eb4207e1ab39344b785a72c
sha256: e7c8915458db610ddac09dd87b544b70a2aaa9f17024ee359ee4a8f39096f3b0
sha512: b3759906e3efdccb2568706ac177ffcccf9931d9ecb37b6da38a3bef7ad31d8a779a33168206150b722b69b9b7b0c0a63dc4427cf5351fd8e81b9f11a3eb0d09
ssdeep: 3072:LGk67jTiVy1aUf9IegvzU/QT62JdAaVH:L363TdzIeX/wbAa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0404 0x04b0
LegalCopyright: Equinix
InternalName: ANDRE
FileVersion: 66.00
CompanyName: Equinix
LegalTrademarks: Equinix
Comments: Equinix
ProductName: Equinix
ProductVersion: 66.00
FileDescription: Equinix
OriginalFilename: ANDRE.exe

Win32/Kryptik.HMOY also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Mucc.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.2fba11
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMOY
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyUDS:Trojan.Win32.Mucc
BitDefenderTrojan.GenericKD.47023890
MicroWorld-eScanTrojan.GenericKD.47023890
Ad-AwareTrojan.GenericKD.47023890
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaCO.34170.hm0@ayRtsfej
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
FireEyeGeneric.mg.83c12d2c11d79a56
EmsisoftTrojan.GenericKD.47023890 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Mucc
MicrosoftTrojan:Win32/Casdet!rfn
GDataTrojan.GenericKD.47023890
AhnLab-V3Win-Trojan/VBKrand.Gen
McAfeeArtemis!83C12D2C11D7
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.F0D1C00IN21
IkarusTrojan.VB.Crypt
FortinetMalicious_Behavior.SB
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HMOY?

Win32/Kryptik.HMOY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment