Malware

Win32/Kryptik.HMUG removal tips

Malware Removal

The Win32/Kryptik.HMUG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMUG virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Estonian
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HMUG?


File Info:

crc32: 00699644
md5: 21d57f314016abccc635b26d1a238042
name: 21D57F314016ABCCC635B26D1A238042.mlw
sha1: 46836ed0c6500a096b3c3db77939b39d47e9c991
sha256: 9096790ce75881a07a3751c611612f9a30fadc0481130c0cdb3562af4ec39b92
sha512: 88a8096077f4870479bf45ab9d2c4144f5b3b11d70fff777709622bb52e8f10b504f3ce5c885fd0302f73538848eea0ad4176bc660d3d38fedef657c9f678dc1
ssdeep: 24576:g6ew4piY1fNs2TV0WUZEe/07a7o4zO90lppmuWcsHZ41/p6c3:cN1fNs2TV0gq07aMF94p9WcsHZIRN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0150 0x051c

Win32/Kryptik.HMUG also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 00584baa1 )
LionicTrojan.Multi.Generic.4!c
DrWebTrojan.DownLoader42.62977
CynetMalicious (score: 100)
ALYacSpyware.Danabot.A
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Azorult.26df893a
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.0c6500
CyrenW32/Kryptik.FLE.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HMUG
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.47115442
MicroWorld-eScanTrojan.GenericKD.47115442
Ad-AwareTrojan.GenericKD.47115442
SophosML/PE-A + Troj/Krypt-DI
ComodoMalware@#246jab6g4wgpv
BitDefenderThetaGen:NN.ZexaF.34170.gzW@a4Tt3Nmk
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.21d57f314016abcc
EmsisoftTrojan.GenericKD.47115442 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.doug
AviraTR/Crypt.Agent.yqtqc
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Azorult.RW!MTB
GDataTrojan.GenericKD.47115442
AhnLab-V3Infostealer/Win.SmokeLoader.R444286
Acronissuspicious
McAfeePacked-GDT!21D57F314016
MAXmalware (ai score=87)
VBA32Malware-Cryptor.Azorult.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H06J521
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Kryptik.HMTX!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HMUG?

Win32/Kryptik.HMUG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment