Malware

Win32/Kryptik.HNJO (file analysis)

Malware Removal

The Win32/Kryptik.HNJO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNJO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HNJO?


File Info:

crc32: 187471B2
md5: 097ce923b3f3bb87af75251a29f425e3
name: 097CE923B3F3BB87AF75251A29F425E3.mlw
sha1: 1ffe446c4a8229093894040e9042139eddec349b
sha256: 0dfab39e2d2ace63ab2492f60ce16ce1da7f602f1ac4847cb71b9c7dc1ed0031
sha512: 3408b00d75a8c2747c3b0aaa488a141f27b418b2f5f2deb166ad75e4295ee31b8b9e1d7654e4e15721c77defe06962541e8bddf3049cc4a71567981ba6dbd764
ssdeep: 3072:G7b4tc9obWA+X0wv8eqWFUyvcdjsZwvNj7e:EUWA+X9v8enUb2Y7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 13.54.37.21
Copyright: Copyrighz (C) 2021, fudkat
Translation: 0x0117 0x046a

Win32/Kryptik.HNJO also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWHacktool ( 700007861 )
Cybereasonmalicious.c4a822
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNJO
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Backdoor.Win32.Mokes.gen
SophosMal/Generic-R + Troj/Krypt-BO
BitDefenderThetaGen:NN.ZexaF.34294.jq0@aWdG7xmO
FireEyeGeneric.mg.097ce923b3f3bb87
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/StopCrypt.PU!MTB
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#85% (RDMK:cmRtazrSsJ10QZWBDuXe+95sGhW8)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ETEM!tr

How to remove Win32/Kryptik.HNJO?

Win32/Kryptik.HNJO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment