Malware

Win32/Kryptik.HHCO removal tips

Malware Removal

The Win32/Kryptik.HHCO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HHCO virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 127.0.0.1:27783
  • A process created a hidden window
  • Unconventionial language used in binary resources: Spanish (Venezuela)
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Attempts to execute a powershell command with suspicious parameter/s
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HHCO?


File Info:

crc32: F036559A
md5: 1eb9711941ce11b4eabfe843fc75dbbb
name: asura.exe
sha1: 8d474e4c28a25ce8dfa485ec3a0830b1074ae9b6
sha256: ac75b0f63e11222ad961de72c3a81ec87aa69e0b6a39bbb58c0777e3aa2c9aa8
sha512: 9e12028945985c75995571b734990f65fe6a41a03deca49d9da30ca10342033fd1b6bfcdf783ec4dea0e4aaf618cd5332f41442219b33e83a18878f6ea0649d3
ssdeep: 98304:BsElQnGaAlHbjyBjd0880I/Jo2xVElRil8oKBvD/Ib7uJI+va:5pakCBn80I/JBDEl8lkBvjcuda
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: wriheawtz.otu
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, gumke
TranslationUsi: 0x0421 0x0ccd

Win32/Kryptik.HHCO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34995304
FireEyeGeneric.mg.1eb9711941ce11b4
McAfeePacked-GCZ!1EB9711941CE
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056fc4c1 )
BitDefenderTrojan.GenericKD.34995304
K7GWTrojan ( 0056fc4c1 )
CrowdStrikewin/malicious_confidence_90% (W)
InvinceaGeneric ML PUA (PUA)
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Generic@ML.100 (RDML:dWDBieo6xW1u5OjkccgASg)
Ad-AwareTrojan.GenericKD.34995304
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
EmsisoftTrojan.GenericKD.34995304 (B)
SentinelOneDFI – Suspicious PE
MicrosoftTrojan:Win32/Azorult.FW!MTB
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan-Stealer.Petef.0OAF4U
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wacatac.R354473
Acronissuspicious
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Kryptik.HHCO
IkarusTrojan.Win32.Glupteba
FortinetMalicious_Behavior.SB
AVGFileRepMetagen [Malware]
Cybereasonmalicious.c28a25
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM10.2.EC52.Malware.Gen

How to remove Win32/Kryptik.HHCO?

Win32/Kryptik.HHCO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment