Malware

Win32/Kryptik.HCWU removal tips

Malware Removal

The Win32/Kryptik.HCWU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCWU virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Bulgarian
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

www.bing.com
devicelease.xyz

How to determine Win32/Kryptik.HCWU?


File Info:

crc32: 55D69709
md5: eaeba1a1735070ac50ac444460eb8362
name: 101go9jn8jc7.exe
sha1: 75f76fa95e83f4f86523051cc87a039aed48aa6a
sha256: 77b558cdf1632ee728dfbb10f2f13aa415a8ff9d72fbd4e5f4874beeae523c7a
sha512: ee54faf6440d47fc9a4771de7d47a0fa983c2990993fd42192cc56e7e142508de15031c4d272e5b752ca56e88b972979a4cffd7447756ef67b66bff65bc5f915
ssdeep: 1536:tV7RSS9YSCSISCShSCSxAGzsCTXYtFBo45GQG770gSvc1RIVLmyLmRgRLuLkutb:JuAGBTYzGHsNv6xgRK4VljQaeA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileDescription: vncagent

Win32/Kryptik.HCWU also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.Gozi.661
MicroWorld-eScanTrojan.GenericKD.33686261
FireEyeGeneric.mg.eaeba1a1735070ac
Qihoo-360HEUR/QVM20.1.C975.Malware.Gen
McAfeeGenericRXAA-AA!EAEBA1A17350
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderTrojan.GenericKD.33686261
K7GWTrojan ( 00564c7f1 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Generic.D20202F5
BitDefenderThetaAI:Packer.B282D9BF1F
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Malware.Regotet-7679254-0
KasperskyHEUR:Trojan-Banker.Win32.Gozi.vho
RisingTrojan.Kryptik!1.C460 (RDMK:cmRtazokRFYJflt5G8Mwqn1KGRQq)
Endgamemalicious (high confidence)
SophosMal/Cerber-AL
F-SecureTrojan.TR/Crypt.Agent.cgnzk
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33686261 (B)
CyrenW32/Trojan.HWDZ-8661
JiangminTrojan.Banker.Gozi.alr
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.cgnzk
FortinetW32/Kryptik.HCRT!tr
Antiy-AVLTrojan[Backdoor]/Win32.Hupigon
MicrosoftTrojan:Win32/Gozi.MS!MTB
ZoneAlarmHEUR:Trojan-Banker.Win32.Gozi.vho
Acronissuspicious
VBA32Trojan.Gozi
ALYacTrojan.GenericKD.33686261
MAXmalware (ai score=81)
Ad-AwareTrojan.GenericKD.33686261
MalwarebytesTrojan.Banker
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HCWU
TencentMalware.Win32.Gencirc.10b9cc47
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_82%
GDataTrojan.GenericKD.33686261
AVGWin32:BankerX-gen [Trj]
Cybereasonmalicious.173507

How to remove Win32/Kryptik.HCWU?

Win32/Kryptik.HCWU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment