Malware

Win32/Kryptik.HOCL removal guide

Malware Removal

The Win32/Kryptik.HOCL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HOCL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Xhosa
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Created a service that was not started
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HOCL?


File Info:

name: 90A37DDD4D0AF6BF329E.mlw
path: /opt/CAPEv2/storage/binaries/b80e9d98ce5567ac4fedfa00d74dbe088ec00aefc81c9484c88d2a63067c4ab3
crc32: B2B35AFC
md5: 90a37ddd4d0af6bf329e80e6bf8262fb
sha1: 3d4ce6e0959959edbf259cc77542f95c80413898
sha256: b80e9d98ce5567ac4fedfa00d74dbe088ec00aefc81c9484c88d2a63067c4ab3
sha512: 7f4942a52dd714195fb1d04b60c492fbf71a3c85ffd7e44a2dfaa58ac76b96a199d6c15c33f3b6c954f77f4b49386d58069ca12503dff401620749618242429d
ssdeep: 49152:zTPYGnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn:zr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190F6AEB4F691955DD45513B0962B8FDA1EACFC486C08576B20B8EB87BE77304EC4222F
sha3_384: dc3012403f19b3fb118294e2ecd07a869dff6b9bb2b491365dca025af1d8cdbe1f54d498e989f58bcf516701ca47895f
ep_bytes: e8c1490000e978feffff8325e4d54300
timestamp: 2020-10-01 12:05:20

Version Info:

FileVersion: 21.29.11.69
InternationalName: bomgveoci.iwa
Copyright: Copyrighz (C) 2021, fudkorta
ProjectVersion: 1.10.74.57
Translations: 0x0121 0x03ca

Win32/Kryptik.HOCL also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83012
FireEyeGeneric.mg.90a37ddd4d0af6bf
McAfeeLockbit-FSWW!90A37DDD4D0A
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Generic.D14444
CyrenW32/Qbot.FK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HOCL
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Mikey-9917879-0
KasperskyHEUR:Trojan.Win32.DiskWriter.gen
BitDefenderTrojan.GenericKDZ.83012
Ad-AwareTrojan.GenericKDZ.83012
EmsisoftTrojan.Crypt (A)
DrWebTrojan.DownLoader44.35198
TrendMicroMal_Tofsee
McAfee-GW-EditionLockbit-FSWW!90A37DDD4D0A
SophosML/PE-A + Mal/Agent-AWV
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftRansom:Win32/StopCrypt.PAR!MTB
ZoneAlarmHEUR:Trojan.Win32.DiskWriter.gen
GDataWin32.Trojan.PSE1.1M4L73C
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.SmokeLoader.R467918
BitDefenderThetaGen:NN.ZexaF.34182.@t0@aenK@wmG
ALYacTrojan.GenericKDZ.83012
MAXmalware (ai score=86)
VBA32TrojanRansom.Stop
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallMal_Tofsee
RisingTrojan.Kryptik!8.8 (RDMK:cmRtazqB6grMrdnuNERoqCEcQdzw)
YandexTrojan.Kryptik!zZ3PnbzMOrE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HOCG!tr
AVGWin32:Malware-gen
Cybereasonmalicious.095995
PandaTrj/GdSda.A

How to remove Win32/Kryptik.HOCL?

Win32/Kryptik.HOCL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment