Malware

Win32/Kryptik.HCBC malicious file

Malware Removal

The Win32/Kryptik.HCBC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCBC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.HCBC?


File Info:

crc32: 87653393
md5: 81a5eea229359c1472ed15a455cc64d5
name: svchost.exe
sha1: a57ea751763841401d7b3b9793d0e6ee74e23602
sha256: 0afe4596b0abc61aff3c66dc68e57c6dd81b8e7ceeaef221c4034f289bf947e6
sha512: 0918740e5ce781d6b9a9d4257bbb78824dd705c1e9c92e962af220cbfca18d2cae5abff97b6346ef54c4b856b9546fba0ccaa0e82125f81eae81347695dc6238
ssdeep: 24576:wkS2NJMhlQPr6b5K7QDfA7YJUWwlSfgcMeu5BMJ9AoGn:wkS2XfshUfpeIMJrA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Comfort Software Group (C) 2007-2015
InternalName: RecycledDecelerated
CompanyName: Comfort Software Group
LegalTrademarks: Comfort Software Group (C) 2007-2015
Comments: Daemon Correlating House Retrspective
ProductName: RecycledDecelerated
ProductVersion: 6.6.1.5
FileDescription: Daemon Correlating House Retrspective
Translation: 0x0409 0x04b0

Win32/Kryptik.HCBC also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33551608
FireEyeGeneric.mg.81a5eea229359c14
ALYacBackdoor.Remcos.A
K7AntiVirusTrojan ( 00562e231 )
BitDefenderTrojan.GenericKD.33551608
K7GWTrojan ( 00562e231 )
TrendMicroMal_HPGen-37b
BitDefenderThetaGen:NN.ZexaF.34100.lr0@aeCwdSpi
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HCBC
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.33551608
KasperskyBackdoor.Win32.Androm.twqm
AlibabaBackdoor:Win32/Androm.63a1d421
ViRobotTrojan.Win32.Z.Agent.1239552
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Backdoor.Androm.Dztl
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.gfghz
DrWebTrojan.PWS.Stealer.23680
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33551608 (B)
IkarusTrojan-Spy.Remcos
CyrenW32/Trojan.MWLM-0005
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.gfghz
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Backdoor]/Win32.Androm
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Generic.D1FFF4F8
AhnLab-V3Trojan/Win32.Agent.C4020384
ZoneAlarmBackdoor.Win32.Androm.twqm
McAfeeArtemis!81A5EEA22935
VBA32BScope.Trojan.Casur
MalwarebytesTrojan.MalPack.RVRS
PandaTrj/CI.A
TrendMicro-HouseCallMal_HPGen-37b
RisingBackdoor.Androm!8.113 (CLOUD)
SentinelOneDFI – Malicious PE
FortinetPossibleThreat.MU
Ad-AwareTrojan.GenericKD.33551608
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win32/Backdoor.86f

How to remove Win32/Kryptik.HCBC?

Win32/Kryptik.HCBC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment