Malware

Win32/Kryptik.HCRH information

Malware Removal

The Win32/Kryptik.HCRH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCRH virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.HCRH?


File Info:

crc32: 05ACEC4B
md5: e493b7441b9c3ac93507308cf3dd8c47
name: Temp.exe
sha1: e9d9dbece925fd6e846e771cb605f6c293979a62
sha256: bc5493c7e717aad7544368a5b3e67f12db92258e04bb23126c3f2e3fae63a3a5
sha512: 6e0c4213f14ac14424e82e978c8aa5fbdd455b2c26fc7a2edbc2c9d36874f0d8b9c207cf62ba2610d41f5b0bafe0bc3517850bbef59633367276a767a36dd196
ssdeep: 3072:371DujChdcl11zmXlc+lGZfHrBftAYYjkMxVBwDkGsI4C/3:3JajYM11DBftAYYjRVBTZI13
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: lsass.exe
FileVersion: 10.0.14393.2580 (rs1_release_inmarket.181009-1745)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.14393.2580
FileDescription: Local Security Authority Process
OriginalFilename: lsass.exe
Translation: 0x0804 0x04b0

Win32/Kryptik.HCRH also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.42985929
McAfeeRDN/Generic.tfr
ALYacTrojan.GenericKD.42985929
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.GenericKD.42985929
K7GWTrojan ( 005648901 )
Cybereasonmalicious.ce925f
TrendMicroTrojan.Win32.MALXMR.BP
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.42985929
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Kryptik.21dd43a5
AegisLabTrojan.Multi.Generic.4!c
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.42985929 (B)
F-SecureHeuristic.HEUR/AGEN.1116853
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e493b7441b9c3ac9
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.OEWT-4703
JiangminTrojan.Inject.aqnl
WebrootW32.Malware.gen
AviraHEUR/AGEN.1116853
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D28FE9C9
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKD.42985929
MalwarebytesTrojan.MalPack
PandaTrj/Agent.AJS
ESET-NOD32a variant of Win32/Kryptik.HCRH
TrendMicro-HouseCallTrojan.Win32.MALXMR.BP
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Kryptik!Sv6MLYivGK4
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HCRH!tr
BitDefenderThetaGen:NN.ZexaF.34106.ku1@aavFo!cj
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HCRH?

Win32/Kryptik.HCRH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment