Malware

Win32/Kryptik.HCSQ removal

Malware Removal

The Win32/Kryptik.HCSQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCSQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Win32/Kryptik.HCSQ?


File Info:

crc32: FABDAEE5
md5: 22409058ef4ca4923e02b76fb8648aba
name: 22409058EF4CA4923E02B76FB8648ABA.mlw
sha1: db1e1781e7fbc6fd079bb1cf3a6d2cfefe29441f
sha256: 96787d289cc3c9c6751f6a959493846d93a51d19cc2614ff4043ba394ff93312
sha512: 38fa76da085fc6d549ab15b3e2885db2aec69aadcab44d7a29e2d92679649e5cc5e7fec80728329e438a0c018f48d0c167d1346c4cf55e82d46a033e843dc28b
ssdeep: 12288:icb6Mm49IH9eddhyhaPT8w0WEGasJIgJtv:icb5dMhQIw0WXJXJtv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Forexact
FileVersion: 11.4.57.21
CompanyName: Open Dental Software
LegalTrademarks: Forexact evencondition her
ProductName: Forexact
ProductVersion: 11.4.57.21
FileDescription: Forexact
OriginalFilename: Enoughthis.exe
Translation: 0x0409 0x04b0

Win32/Kryptik.HCSQ also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.338941
FireEyeGeneric.mg.22409058ef4ca492
CAT-QuickHealTrojan.Caynamer
McAfeeArtemis!22409058EF4C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zusy.4!c
K7AntiVirusTrojan ( 00564a801 )
BitDefenderGen:Variant.Zusy.338941
K7GWTrojan ( 00564a801 )
TrendMicroTROJ_GEN.R06EC0WKK20
BitDefenderThetaGen:NN.ZexaF.34634.Ju0@aSHWUrji
CyrenW32/Trojan.VJPB-3168
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Gozi-6857634-0
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
AlibabaTrojanBanker:Win32/Kryptik.a5c492f6
TencentMalware.Win32.Gencirc.11b13afc
Ad-AwareGen:Variant.Zusy.338941
TACHYONBanker/W32.Gozi.579072
EmsisoftGen:Variant.Zusy.338941 (B)
ComodoMalware@#a67zof470cai
F-SecureTrojan.TR/Crypt.Agent.bumgy
DrWebTrojan.PWS.Papras.3654
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.bumgy
Antiy-AVLTrojan[Banker]/Win32.Cridex
MicrosoftTrojan:Win32/Ymacco.AA96
ArcabitTrojan.Zusy.D52BFD
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.gen
GDataGen:Variant.Zusy.338941
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.C3020091
Acronissuspicious
ALYacGen:Variant.Zusy.338941
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.RVRS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HCSQ
TrendMicro-HouseCallTROJ_GEN.R06EC0WKK20
RisingRansom.Locky!8.1CD4 (TFE:4:xVEBRbcNJBB)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Gozi.AXN!tr
MaxSecureTrojan.Malware.74474672.susgen
AVGWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Trojan.8a8

How to remove Win32/Kryptik.HCSQ?

Win32/Kryptik.HCSQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment