Malware

What is “Win32/Kryptik.HCGY”?

Malware Removal

The Win32/Kryptik.HCGY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCGY virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests information related to installed instant messenger clients

Related domains:

2ip.ua
frankinshteyn.ru

How to determine Win32/Kryptik.HCGY?


File Info:

crc32: 09EB0B01
md5: 2e67fb98e5b6aa682a383c2b47c7bf8e
name: 2E67FB98E5B6AA682A383C2B47C7BF8E.mlw
sha1: fe2793b4b84be11a8be7ac1e454cbbcf413ddafa
sha256: 3cd2ecb72177621242168eb36ee23e03bd054dc82f8c11b394d69bbd8c86b743
sha512: cae0c6a04c4d5d0bfb6e079fa5e86200b61f89ea01be6a1839564bfea75f34fb26b6cc73ec7d788ee25e8c25393dde3c6cdda256c96db7b17b858e92b591ecd6
ssdeep: 6144:2ovFUihsXa5Nflk6Tv3eg4YTet4SWWLk5:2ovFb6GT3DSDg
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HCGY also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45002262
McAfeeRDN/Generic PWS.y
CylanceUnsafe
AegisLabTrojan.Win32.Tepfer.i!c
SangforMalware
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderTrojan.GenericKD.45002262
K7GWTrojan ( 00563b091 )
K7AntiVirusTrojan ( 00563b091 )
ArcabitTrojan.Generic.D2AEAE16
CyrenW32/Trojan.CHUK-0217
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HCGY
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Tepfer.psyvnp
AlibabaTrojanPSW:Win32/Tepfer.d85d2678
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Generic@ML.99 (RDMK:gQ1IBqjPZbkEhkYTN3CbFg)
Ad-AwareTrojan.GenericKD.45002262
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Carberp.2630
McAfee-GW-EditionBehavesLike.Win32.Generic.bt
FireEyeGeneric.mg.2e67fb98e5b6aa68
EmsisoftTrojan.GenericKD.45002262 (B)
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA3C
ZoneAlarmTrojan-PSW.Win32.Tepfer.psyvnp
GDataTrojan.GenericKD.45002262
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Waldek
ALYacSpyware.PWS.Tepfer.Gen
TACHYONTrojan-PWS/W32.Tepfer.775680.D
MalwarebytesSpyware.Taurus
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CLE20
TencentWin32.Trojan.Crypt.Html
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HCGY!tr
BitDefenderThetaGen:NN.ZexaF.34688.VuW@aOAQQuaG
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.4b84be
AvastWin32:BankerX-gen [Trj]
Qihoo-360Win32/Trojan.PSW.9ee

How to remove Win32/Kryptik.HCGY?

Win32/Kryptik.HCGY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment