Malware

Win32/Kryptik.HCYD removal

Malware Removal

The Win32/Kryptik.HCYD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCYD virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HCYD?


File Info:

crc32: 4F99A54C
md5: 2cf20a1dd3693b996de4a559f1067850
name: 2CF20A1DD3693B996DE4A559F1067850.mlw
sha1: 6483bb40a7e3817f93a3ae95c6caea01715a4946
sha256: f6210da7865e00351c0e79464a1ba14a8ecc59dd79f650f2ff76f1697f6807b1
sha512: 4b817b777ce29fa2e633dd42ca6b849d5e708eb4968e65f49aed99ecf57e38c122229bc075dc996cf944e33e4a30b1a59179a3740ccd86177dff211ce4c48099
ssdeep: 6144:ztKJnv0N4sc6UKOahwyl2bbuBD9t4Piqqb5wVhFsbnN8ef:pKJnv0N4sd7l1R9Ua5wVoz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: CMSTP
FileVersion: 7.02.7601.17514 (win7sp1_rtm.101119-1850)
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Connection Manager
ProductVersion: 7.02.7601.17514
FileDescription: Microsoft Connection Manager Profile ikstaller
OriginalFilename: CMSTP.EXE
Translation: 0x0409 0x04b0

Win32/Kryptik.HCYD also known as:

K7AntiVirusTrojan ( 0056589c1 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.39113
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.66726
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1992187
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:Win32/Kryptik.9fa3349c
K7GWTrojan ( 005655711 )
Cybereasonmalicious.dd3693
CyrenW32/Trojan.MQNW-1554
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.HCYD
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Dropper.Qakbot-7686012-0
KasperskyHEUR:Trojan-Banker.Win32.Qbot.vho
BitDefenderTrojan.GenericKDZ.66726
NANO-AntivirusTrojan.Win32.Qbot.horxjz
SUPERAntiSpywareTrojan.Agent/Gen-QBot
MicroWorld-eScanTrojan.GenericKDZ.66726
TencentMalware.Win32.Gencirc.10b9eaa9
Ad-AwareTrojan.GenericKDZ.66726
SophosMal/Generic-R + Mal/EncPk-APV
ComodoTrojWare.Win32.Qbot.AD@8r7ef8
F-SecureTrojan.TR/AD.Qbot.jggna
BitDefenderThetaGen:NN.ZexaF.34670.3r0@a85Y9mgi
VIPRETrojan.Win32.Generic!BT
TrendMicroBackdoor.Win32.QAKBOT.SME
McAfee-GW-EditionBehavesLike.Win32.Dropper.tz
FireEyeGeneric.mg.2cf20a1dd3693b99
EmsisoftTrojan.GenericKDZ.66726 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.Qbot.nv
WebrootW32.Trojan.Gen
AviraTR/AD.Qbot.jggna
Antiy-AVLTrojan[Banker]/Win32.Qbot
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftRansom:Win32/Shade
GridinsoftTrojan.Win32.Kryptik.ba!s3
ArcabitTrojan.Generic.D104A6
AegisLabTrojan.Win32.Qbot.7!c
ZoneAlarmHEUR:Trojan-Banker.Win32.Qbot.vho
GDataTrojan.GenericKDZ.66726
TACHYONBackdoor/W32.QBot.1950208
AhnLab-V3Trojan/Win32.QBot.R334198
Acronissuspicious
McAfeeW32/PinkSbot-GN!2CF20A1DD369
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Shade
MalwarebytesTrojan.Qbot
PandaTrj/Genetic.gen
TrendMicro-HouseCallBackdoor.Win32.QAKBOT.SME
RisingBackdoor.Qakbot!8.C7B (TFE:dGZlOgLn4a1PkkDgNA)
YandexTrojan.GenKryptik!tLHL/zQ8A48
IkarusTrojan.Win32.Qbot
MaxSecureTrojan.Malware.90497350.susgen
FortinetW32/Kryptik.DZZ!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.QakBot.HxQB8TsA

How to remove Win32/Kryptik.HCYD?

Win32/Kryptik.HCYD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment