Malware

Should I remove “Win32/Kryptik.HCNR”?

Malware Removal

The Win32/Kryptik.HCNR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCNR virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Unconventionial language used in binary resources: Romanian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HCNR?


File Info:

crc32: 8F5A4029
md5: f161805b402a3d7cf45d0c189c71f0ae
name: browser_update.exe
sha1: c3ccf1eb40121badaf8320b63d3dbfb1b6f5430e
sha256: 901bc34790c7ccbad3e3336d17e4ec2c04add5a210125052bb793c27010ae455
sha512: 03254b6aba2d94095c92cef4aa0bdb96fea28c3a0db0656a4aa0a37c4372e67fa5a6faa828cda377cdb51bf2a46087edf5878a6e8b6cc9d7c31a923bf80b06cf
ssdeep: 12288:vIhJyQUElBg/ROX0FVJ9QUSTrS6obz6hHksQ:QhJyQUE0pOXoee646yb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HCNR also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Siggen9.34209
MicroWorld-eScanTrojan.GenericKDZ.66191
Qihoo-360HEUR/QVM10.1.68E9.Malware.Gen
McAfeeArtemis!F161805B402A
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKDZ.66191
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34106.AqY@a4DLFNkG
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKDZ.66191
KasperskyTrojan-PSW.Win32.Racealer.ejs
RisingTrojan.Kryptik!1.C359 (CLASSIC)
Ad-AwareTrojan.GenericKDZ.66191
SophosMal/RyPack-A
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.f161805b402a3d7c
EmsisoftTrojan.GenericKDZ.66191 (B)
IkarusTrojan.Win32.Crypt
WebrootW32.Trojan.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.DC6410
ZoneAlarmTrojan-PSW.Win32.Racealer.ejs
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Trojan/Win32.MalPe.R331570
Acronissuspicious
ALYacGen:Variant.Ursu.812048
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HCNR
TrendMicro-HouseCallTROJ_GEN.R015H09D720
YandexTrojan.Shelma!
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/Kryptik.HBNS!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.HCNR?

Win32/Kryptik.HCNR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment