Malware

Win32/Kryptik.HCCL removal tips

Malware Removal

The Win32/Kryptik.HCCL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCCL virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HCCL?


File Info:

crc32: AE5DA721
md5: 0772374b7f3b8560a9434d8e42114adc
name: vps.exe
sha1: 64807a8a080ece8539e7319d5582e4b256ca0c83
sha256: be3ffa4fee7aed9799337687ebb6c36204e16b9cb4be04053e1448f1e8e48dfa
sha512: 3c4d8f20ecbb2a60109a28e04eb6280a5f8486de40c99e7d4915740a5f13fdc0778f5ce7878cdcc85ce5894c6584826ddef5484f9eabcc6aa33db74176f7bdce
ssdeep: 12288:WNuKKKuz3mUEJ1hm6vEWPTF0er/jq/SwFy:rKamUCD0ek
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HCCL also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42864152
Qihoo-360Win32/Trojan.BO.7ea
McAfeeArtemis!0772374B7F3B
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.42864152
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Generic.D28E0E18
Invinceaheuristic
CyrenW32/CoinMiner.BL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HCCL
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
KasperskyTrojan-Banker.Win32.Danabot.ekf
AegisLabTrojan.Multi.Generic.4!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42864152 (B)
McAfee-GW-EditionBehavesLike.Win32.Ransomware.hc
FortinetPossibleThreat.MU
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.0772374b7f3b8560
SophosMal/RyPack-A
IkarusTrojan-Downloader.Win32.Zurgop
F-ProtW32/CoinMiner.BL.gen!Eldorado
WebrootW32.Trojan.Gen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Azorult.KMG!MTB
ZoneAlarmTrojan-Banker.Win32.Danabot.ekf
Acronissuspicious
Ad-AwareTrojan.GenericKD.42864152
MalwarebytesSpyware.RaccoonStealer
RisingTrojan.Kryptik!1.C412 (CLASSIC)
SentinelOneDFI – Suspicious PE
GDataWin32.Packed.Kryptik.X2Q7RX
BitDefenderThetaGen:NN.ZexaF.34100.JuW@aSRTKFF
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HCCL?

Win32/Kryptik.HCCL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment