Malware

Win32/Kryptik.MHU removal

Malware Removal

The Win32/Kryptik.MHU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.MHU virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.MHU?


File Info:

name: 2E4DAD3EB8E174185F0B.mlw
path: /opt/CAPEv2/storage/binaries/b420f8f9b76f6a0d65d1f4d548b6c7fc2537bfd9fedc8c52b25aa59571ee9e09
crc32: 0FCA8BCC
md5: 2e4dad3eb8e174185f0bbe441ddffd7d
sha1: ddffb7af6e247167ccf4e3778bc75af61959db6a
sha256: b420f8f9b76f6a0d65d1f4d548b6c7fc2537bfd9fedc8c52b25aa59571ee9e09
sha512: 08cef58b386249e7190aa6eb8fda722a5edc1535b79126b63e66cfeced601fd6b080e91265deb8240ca775629e06afdd04c02eb92d1de6200eb5b86ade2f12e4
ssdeep: 98304:kBuGoEd+inMgKr9fijgRQorMoxUlkMl84nux3Skv3SkIDb/YLiA:koGoDFr9mgRQortxUlX84nrfkCbwLiA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F3633016684EE5DE2858FBAE687C3F1C2C51D83FB18449369AA3FD3F277956209F244
sha3_384: 8d512a7b9d826e6132931367eb88f664a6e7d98bc650595ba68f8e2042528ab6d9ab7293e9fc3dbdb945f39c81413417
ep_bytes: 60be0040d1008dbe00d06effc787ec70
timestamp: 2008-12-02 15:41:29

Version Info:

0: [No Data]

Win32/Kryptik.MHU also known as:

LionicHacktool.Win32.ArchSMS.lmoi
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.473
MicroWorld-eScanGen:Variant.Adware.SMSHoax.25
FireEyeGeneric.mg.2e4dad3eb8e17418
CAT-QuickHealHoax.Archsms.21852
McAfeeGenericRXAA-AA!2E4DAD3EB8E1
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforVirus.Win32.Vigorf.A
K7AntiVirusTrojan ( 004e62231 )
AlibabaVirTool:Win32/Obfuscator.606e34d1
K7GWTrojan ( 004e62231 )
Cybereasonmalicious.eb8e17
BitDefenderThetaAI:Packer.BA9DBEF320
VirITTrojan.Win32.SMSSend.SF
CyrenW32/Kryptik.DKT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.MHU
TrendMicro-HouseCallTROJ_DIPLE.CFR
ClamAVWin.Trojan.Agent-1017783
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Adware.SMSHoax.25
NANO-AntivirusRiskware.Win32.ArchSMS.utmvj
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b4b1f8
Ad-AwareGen:Variant.Adware.SMSHoax.25
EmsisoftGen:Variant.Adware.SMSHoax.25 (B)
ComodoMalware@#nkeqh0io39ut
ZillyaTrojan.ArchSMS.Win32.377
TrendMicroTROJ_DIPLE.CFR
McAfee-GW-EditionW32/Pinkslipbot.gen.ae
SophosMal/Generic-R + Mal/EncPk-ZC
Ikarusnot-a-virus:Hacktool.SMSHoax
GDataGen:Variant.Adware.SMSHoax.25
JiangminHoax.ArchSMS.bcm
WebrootW32.Adware.Gen
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Ditertag.A
ALYacGen:Variant.Adware.SMSHoax.25
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!K9QWYfIJ3gg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
AVGWin32:Adware-gen [Adw]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Win32/Kryptik.MHU?

Win32/Kryptik.MHU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment