Malware

How to remove “Win32/Kryptik.HCDO”?

Malware Removal

The Win32/Kryptik.HCDO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCDO virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HCDO?


File Info:

crc32: 70B4554F
md5: f377f0c260a1a0cb057bfa57aab1fd85
name: vps.exe
sha1: 0573148f5fe873cc8726ca65bb4fbfde514aa7e0
sha256: 982b2cf00134876aec30d9447630733b7f2258766f4a6c3d1b0b5884ca1c1fe0
sha512: 3bd3cfe9b2a354c7cac3613901d2260ba3362ec24c1dc151753033780f3932d5a028af5128ecd59004f14eac07f2328685213d5692949845790b83370647659f
ssdeep: 12288:j4+DRNb8U/ArjO9w4GEKWh5qtu+t0ufeoojXVYaJNMk4:j3Np/AYaagtp0ulojxN
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HCDO also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.42870308
FireEyeGeneric.mg.f377f0c260a1a0cb
Qihoo-360Win32/Trojan.BO.48c
McAfeeArtemis!F377F0C260A1
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0053d5971 )
BitDefenderTrojan.GenericKD.42870308
K7GWTrojan ( 0053d5971 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R011C0DCN20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.42870308
KasperskyTrojan-Banker.Win32.Danabot.eli
ViRobotTrojan.Win32.Z.Rypack.585728
RisingTrojan.Kryptik!8.8 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42870308 (B)
ComodoMalware@#2nawtauqhi7vh
F-SecureTrojan.TR/Crypt.Agent.rxioc
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
SophosMal/RyPack-A
IkarusTrojan.Win32.Crypt
JiangminBackdoor.Tofsee.brb
AviraTR/Crypt.Agent.rxioc
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D28E2624
ZoneAlarmTrojan-Banker.Win32.Danabot.eli
MicrosoftTrojan:Win32/Racealer.DSK!MTB
AhnLab-V3Trojan/Win32.MalPe.R329480
Acronissuspicious
VBA32BScope.Trojan.AET.281105
ALYacTrojan.GenericKD.42870308
MAXmalware (ai score=88)
Ad-AwareTrojan.GenericKD.42870308
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HCDO
TrendMicro-HouseCallTROJ_GEN.R011C0DCN20
TencentWin32.Trojan-banker.Danabot.Ebzz
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.A!tr
BitDefenderThetaGen:NN.ZexaF.34100.JuW@aOcnd1G
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HCDO?

Win32/Kryptik.HCDO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment