Malware

How to remove “Win32/Kryptik.HMZT”?

Malware Removal

The Win32/Kryptik.HMZT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMZT virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua

How to determine Win32/Kryptik.HMZT?


File Info:

crc32: EB80FD79
md5: a8e7d4fa0654318f38d94f7bdb3b2636
name: A8E7D4FA0654318F38D94F7BDB3B2636.mlw
sha1: 3eb6adfb1a82a454460df843e36b6d0f42de6add
sha256: ab279cfb5f6340d71aca6fd7cb5d66844be83ebb582b93a7b93230f598fc6b5d
sha512: 728e901fd09f14336c7aafad371e752c91bb277667457e624d0a8e8d019beb47481d343707b1a7a4b450185659388548b19768496853507345c78ddef2325fa5
ssdeep: 24576:pjYIRIHUbGI3LllMMp2oT6l2lyh7OpT/:Ocia3hldpXT6lph7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0452 0x0011

Win32/Kryptik.HMZT also known as:

K7AntiVirusTrojan ( 005690671 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Stop
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 005690671 )
Cybereasonmalicious.b1a82a
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FOO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMZT
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Dropper.Tofsee-9903298-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKD.47221406
MicroWorld-eScanTrojan.GenericKD.47221406
Ad-AwareTrojan.GenericKD.47221406
FireEyeGeneric.mg.a8e7d4fa0654318f
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.InstaBot.ycwzq
MicrosoftRansom:Win32/StopCrypt.MNK!MTB
GDataWin32.Trojan.PSE.7PWGA6
AhnLab-V3Packed/Win.GDT.R446567
Acronissuspicious
McAfeePacked-GDT!A8E7D4FA0654
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#80% (RDMK:cmRtazo2Cz28xcUQpqxns0hvNk4O)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FMKI!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Win32/Kryptik.HMZT?

Win32/Kryptik.HMZT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment