Malware

Win32/Kryptik.HNHZ removal tips

Malware Removal

The Win32/Kryptik.HNHZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNHZ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HNHZ?


File Info:

crc32: E472D427
md5: b641802986992824c8e5a5d64af0eb8c
name: B641802986992824C8E5A5D64AF0EB8C.mlw
sha1: ccdbcd140452a95252a0f8cd0d219c8f929fe337
sha256: 0968b29bbd4b8fed0ac21df64fd5e7a0012fcb215f1e058549d8636d4a4af240
sha512: 86ebe3805de2bbd125672a75f56e1edcc32420311c47d0f3ebc42a2f96f5d11783fd63c39c218a8658da4ea8b40059494e2e094def18424622e828d16136bd95
ssdeep: 6144:e4VAGAFfLF660EExWeFPBy7ITsq7igavwVf:jCGAFf3IS79
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 15.54.17.21
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0184 0x046a

Win32/Kryptik.HNHZ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader43.65090
ClamAVWin.Packed.Fragtor-9908420-0
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.907cd77a
K7GWHacktool ( 700007861 )
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecPacked.Generic.528
ESET-NOD32a variant of Win32/Kryptik.HNHZ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.38022824
MicroWorld-eScanTrojan.GenericKD.38022824
Ad-AwareTrojan.GenericKD.38022824
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.nq0@aybLUcdO
McAfee-GW-EditionBehavesLike.Win32.Worm.dh
FireEyeGeneric.mg.b641802986992824
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_95%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Casdet!rfn
GDataWin32.Trojan-Downloader.SmokeLoader.MPR69V
Acronissuspicious
McAfeeLockbit-FSWW!B64180298699
MAXmalware (ai score=89)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H06KE21
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazr11V04Z2wN5z9iN2xXZCcy)
IkarusTrojan-Ransom.StopCrypt
FortinetW32/Lockbit.FSWW!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Win32/Kryptik.HNHZ?

Win32/Kryptik.HNHZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment