Malware

Win32/Kryptik.HMRX removal guide

Malware Removal

The Win32/Kryptik.HMRX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMRX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Hungarian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HMRX?


File Info:

crc32: 70B64927
md5: 92059948d7c9d55b9a93939f577212e4
name: 92059948D7C9D55B9A93939F577212E4.mlw
sha1: edef6e678a75bd9e578194d481ef62e2b7d66806
sha256: f23ad612df5b25814d5448be9505bc76b8b763dfd622e69a4915736fad6d9d55
sha512: 2b6aa465fecb029efe8dfa95b1dbeb969f50c2e4fe5683ddff7d237a6b732ff98f8f0dd6fce5baa732d774b3d77630c240769edaad8449db23609d55b3b62bb0
ssdeep: 6144:5N1wylcPCd3l1J+bFBuLeeYx38wPJCJnxExpqJL6siOOhxxdeTr/ekI:hLWCRUBTJx8EyL6sYzxd6L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sajbmianozu.iya
ProductVersion: 8.64.59.52
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0527 0x007a

Win32/Kryptik.HMRX also known as:

K7AntiVirusTrojan ( 0058838d1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47088198
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.caad9bc5
K7GWTrojan ( 0058838d1 )
Cybereasonmalicious.78a75b
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMRX
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderTrojan.GenericKD.47088198
MicroWorld-eScanTrojan.GenericKD.47088198
Ad-AwareTrojan.GenericKD.47088198
SophosMal/Generic-S + Troj/Krypt-CY
BitDefenderThetaGen:NN.ZexaF.34170.yq1@a4qq70nO
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fc
FireEyeGeneric.mg.92059948d7c9d55b
EmsisoftTrojan.GenericKD.47088198 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Tofsee.evu
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.FW!MTB
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.GenericKD.47088198
AhnLab-V3Infostealer/Win.SmokeLoader.R443617
Acronissuspicious
McAfeePacked-GDT!92059948D7C9
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:HUa4vyFmaZRqP5u6xTGP4w)
IkarusTrojan-Banker.UrSnif
FortinetW32/GenKryptik.FLKL!tr
AVGWin32:PWSX-gen [Trj]

How to remove Win32/Kryptik.HMRX?

Win32/Kryptik.HMRX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment