Malware

How to remove “Win32/Kryptik.HCFS”?

Malware Removal

The Win32/Kryptik.HCFS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCFS virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Win32/Kryptik.HCFS?


File Info:

crc32: F2440067
md5: bb73fafe97390f55a5d0182b1b2bd4ef
name: svr11.exe
sha1: a29612b5d4f324ea17eb7c9303bfb8b4202994c3
sha256: 8b35aa930dd7260060f12ff92f1447850fc1a6bd79a28ba05a2d4e54a3aad504
sha512: c7afacf515200ab87ef4aca279a20380b6e70361d54ac3bdda3e271b80e163a12079717b96cac58a2683f259ac2d2e759ee86a44db8de00b33cbc54d4b59a948
ssdeep: 24576:lhm8Dh1KrXsGJtDeZiSNA2tz/62fTsawDb3mtYek88EDK:eM8TR+Z79wXBD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000-2004 Hans Dietrich
FileVersion: 1, 2, 0, 1
ProductName: XBitArrayTest
E-mail: hdietrich2@hotmail.com
ProductVersion: 1, 2, 0, 1
FileDescription: XBitArrayTest.exe
OriginalFilename: XBitArrayTest.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.HCFS also known as:

MicroWorld-eScanTrojan.GenericKD.33706234
CAT-QuickHealTrojan.ArpRI.S12248937
McAfeeArtemis!BB73FAFE9739
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.GenericKD.33706234
K7GWTrojan ( 005634b51 )
CrowdStrikewin/malicious_confidence_60% (D)
TrendMicroTrojanSpy.Win32.EMOTET.TIABOFIR
APEXMalicious
AvastWin32:BankerX-gen [Trj]
GDataWin32.Trojan.Kryptik.PVOQNK
KasperskyTrojan.Win32.Zenpak.zqp
AlibabaTrojan:Win32/Emotet.94933a64
RisingTrojan.MalCert!1.C466 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftMalCert.A (A)
F-SecureTrojan.TR/AD.Swrort.ycwzw
DrWebTrojan.Encoder.31429
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.bb73fafe97390f55
SophosMal/BadCert-Gen
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
AviraTR/AD.Swrort.ycwzw
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Emotet.BF!MTB
ArcabitTrojan.Generic.D20250FA
ZoneAlarmTrojan.Win32.Zenpak.zqp
AhnLab-V3Malware/Win32.RL_Generic.R330046
Ad-AwareTrojan.GenericKD.33706234
MalwarebytesTrojan.Injector
ESET-NOD32a variant of Win32/Kryptik.HCFS
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.TIABOFIR
FortinetW32/Emotet.CD!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.653

How to remove Win32/Kryptik.HCFS?

Win32/Kryptik.HCFS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment