Malware

Win32/Kryptik.HCBS removal guide

Malware Removal

The Win32/Kryptik.HCBS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCBS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

cpf-th.com

How to determine Win32/Kryptik.HCBS?


File Info:

crc32: 5222FFD6
md5: a1426d2a4fabe6fc87426bf32b8ca9b9
name: regasm.exe
sha1: cb358bd68b5f02fa514aec78c7b69bf12640b141
sha256: 5c14b0306ff36f187d26a02ee087872c1447e33dcbf424c59f17a2b971d8d9b6
sha512: d8d2be0fc3c042e64bb9d5ef2ebb47028452a753a5724593b6de144d6ac66f3f320bda36b8bd82b038209322fc7dbbe1d4722bf505153ac877b46e3b3c8dd89f
ssdeep: 12288:cai2m7ydDl7Yxtal7YBpV+HzHDoXAC0hXHTO8BQuqe6pK1CthVAUzrHAEeafUpsR:zldDWg4JOXBLnQAt53zWQHggPdG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)Carbon3D 2007-2015
InternalName: Astronomical
FileVersion: 2.2.1.8
CompanyName: Carbon3D
FileDescription: Smile Predictions Redist Archie Guid
LegalTrademarks: (C)Carbon3D 2007-2015
Comments: Smile Predictions Redist Archie Guid
ProductName: Astronomical
ProductVersion: 2.2.1.8
PrivateBuild: 2.2.1.8
OriginalFilename: Astronomical
Translation: 0x0409 0x04b0

Win32/Kryptik.HCBS also known as:

BkavW32.AIDetectVM.malware
FireEyeGeneric.mg.a1426d2a4fabe6fc
McAfeeArtemis!A1426D2A4FAB
Cybereasonmalicious.68b5f0
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34100.ar0@a07K66fi
SymantecML.Attribute.HighConfidence
GDataWin32.Trojan-Stealer.LokiBot.08Z1T1
KasperskyBackdoor.Win32.Androm.twvr
AegisLabTrojan.Multi.Generic.4!c
APEXMalicious
DrWebTrojan.PWS.Siggen2.45182
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
Trapminemalicious.moderate.ml.score
SentinelOneDFI – Suspicious PE
Endgamemalicious (high confidence)
ZoneAlarmBackdoor.Win32.Androm.twvr
MicrosoftTrojan:Win32/Wacatac.C!ml
Acronissuspicious
VBA32BScope.Trojan.Occamy
ESET-NOD32a variant of Win32/Kryptik.HCBS
RisingBackdoor.Androm!8.113 (CLOUD)
eGambitUnsafe.AI_Score_100%
FortinetW32/Kryptik.HCBS!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win32/Backdoor.5e5

How to remove Win32/Kryptik.HCBS?

Win32/Kryptik.HCBS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment