Malware

Win32/Kryptik.HCZF removal instruction

Malware Removal

The Win32/Kryptik.HCZF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HCZF virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Behavior consistent with a dropper attempting to download the next stage.
  • Network activity contains more than one unique useragent.
  • Collects information about installed applications
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

flytortuga.com
iplogger.org
www.bing.com
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine Win32/Kryptik.HCZF?


File Info:

crc32: EF8693E0
md5: d7ce4266435a0215093c1e676ed20916
name: wotsuper2.exe
sha1: 1718b5be2ef170957fae4522f16e27862e909a0b
sha256: f170fc3c32fa7014a79b20f19c74e4f682ef6edead1a4cc1d0b9989d12cf1d49
sha512: a286f7cc1e0d66cee35baa20fe38bbdad720b2d96e948358a43d4feaf4c1a855570620b464ff1395204a11246e944710e46c5c7757387776709066ed24e7af94
ssdeep: 12288:pANwRo+mv8QD4+0V16jhyNI3MW0cMz689TzLXZ62hhew1DkWEFaTWbJ:pAT8QE+kahyNWMWvdIdjjewmDaabJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: wotsuper
FileDescription: wotsuper 2.1 Installation
FileVersion: 2.1
Comments:
CompanyName: wotsuper
Translation: 0x0409 0x04e4

Win32/Kryptik.HCZF also known as:

DrWebTrojan.Siggen9.41859
MicroWorld-eScanGen:Variant.Razy.439913
FireEyeGeneric.mg.d7ce4266435a0215
McAfeeArtemis!C371DDF0F502
CylanceUnsafe
BitDefenderGen:Variant.Razy.439913
Cybereasonmalicious.6435a0
BitDefenderThetaGen:NN.ZexaF.34108.rqW@aCD!I1lK
AvastWin32:PWSX-gen [Trj]
GDataGen:Variant.Razy.439913
KasperskyTrojan.Win32.Chapak.elhs
Endgamemalicious (moderate confidence)
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1113288
Invinceaheuristic
Trapminemalicious.moderate.ml.score
EmsisoftTrojan-Dropper.Agent (A)
IkarusTrojan-PSW.Agent
eGambitUnsafe.AI_Score_99%
AviraTR/Kryptik.neadm
Antiy-AVLTrojan[PSW]/Win32.Vidar
ArcabitTrojan.Razy.D6B669
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan.Win32.Chapak.elhs
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Malware/Win32.Generic.C3733562
VBA32BScope.Backdoor.Predator
MAXmalware (ai score=82)
MalwarebytesTrojan.Downloader
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HCZF
RisingStealer.Vidar!1.B80D (CLOUD)
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetW32/Agent.OGR!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
Qihoo-360HEUR/QVM05.1.DE10.Malware.Gen

How to remove Win32/Kryptik.HCZF?

Win32/Kryptik.HCZF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment