Malware

About “Win32/Kryptik.HCBP” infection

Malware Removal

The Win32/Kryptik.HCBP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCBP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HCBP?


File Info:

crc32: A78A06F4
md5: a47d2424a2df2e12e4ff06e0bbbea0cf
name: vps.exe
sha1: c323c6fd03de8917be57d4b7121a1b42312b4c90
sha256: de289f8f15c7dcce8adfb75cda25a1c1bca502a7673b97871bf466fc38be9045
sha512: 51b860975e78edcb0b4ab3204b0ef1cf10eae94a21eab4cc81a871643957b1541f2f90e87ab3510ce70d2c314ca97413385462d5c1324d342bbcd79509c0547b
ssdeep: 12288:FpD1VoNoVM0oIq/dBW7M6aR8AN8vAyvP6RKsqW:FpD16NoVMv9/gghqvjvSR8W
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HCBP also known as:

BkavW32.AIDetectVM.malware2
FireEyeGeneric.mg.a47d2424a2df2e12
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_60% (D)
K7GWHacktool ( 700007861 )
BitDefenderThetaGen:NN.ZexaF.34100.JyW@ayZFqqE
CyrenW32/CoinMiner.BL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
GDataWin32.Packed.Kryptik.61E83E
KasperskyUDS:DangerousObject.Multi.Generic
APEXMalicious
SophosMal/RyPack-A
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.hc
Trapminesuspicious.low.ml.score
SentinelOneDFI – Malicious PE
F-ProtW32/CoinMiner.BL.gen!Eldorado
Endgamemalicious (high confidence)
ZoneAlarmTrojan-Banker.Win32.Danabot.ejn
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Trojan/Win32.MalPe.R329207
Acronissuspicious
MalwarebytesRansom.Ryuk
ESET-NOD32a variant of Win32/Kryptik.HCBP
RisingTrojan.Generic@ML.98 (RDML:eEAuwiCGbBQ+DtrRdJ2K5w)
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove Win32/Kryptik.HCBP?

Win32/Kryptik.HCBP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment