Trojan

What is “Crypt.Trojan.Malicious.DDS”?

Malware Removal

The Crypt.Trojan.Malicious.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Crypt.Trojan.Malicious.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Crypt.Trojan.Malicious.DDS?


File Info:

name: 05EC50FABAAF9119621C.mlw
path: /opt/CAPEv2/storage/binaries/3a0716129a24a0348f167d77446badb7dba10e98d6154193c898c83aebaa37df
crc32: 6FCE8B30
md5: 05ec50fabaaf9119621c670152bed113
sha1: 1d05851e6866ce13bb0612b59af7ac27ee4b36cd
sha256: 3a0716129a24a0348f167d77446badb7dba10e98d6154193c898c83aebaa37df
sha512: eedf26b58f41c7b265bd04d28d0b3aa5911dccebeb2bb6c750c1f9962b7f9e938823a1fed5b67d217ad2312eb6e07cf86b7c20ee92804ef778115d7e75524cf5
ssdeep: 24576:68fbil31ZMEWaymEC86M9YJZB91xVeE+Q0Rw:68jil31ZWDOQ2wE+rR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11F45CF12A3E61252D2F6B5B1943F3F9479F96B05A7109CFF16502CCA6A21DF0B936383
sha3_384: 49ce12b2a4c4cba5008d1e863b9886d061a97a30ea70a83ac7132f8baab62d1a3ddccdc6e4dc998a67f7a26ac6676337
ep_bytes: 558bec6aff681808470068d4a4460064
timestamp: 2020-05-15 09:04:05

Version Info:

CompanyName: KC Softwares
FileDescription: AudioGrail
FileVersion: 7.11.4.218
InternalName: AudioGrail
LegalCopyright: KC Softwares SARL
LegalTrademarks: KC Softwares SARL
OriginalFilename: kmp3.exe
ProductName: AudioGrail
ProductVersion: 7.11.4.218
Comments:
Translation: 0x040c 0x04e4

Crypt.Trojan.Malicious.DDS also known as:

LionicTrojan.Win32.Ekstak.4!c
AVGWin32:AdwareX-gen [Adw]
Elasticmalicious (high confidence)
FireEyeGeneric.mg.05ec50fabaaf9119
McAfeeGenericRXKR-DE!05EC50FABAAF
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0059551b1 )
AlibabaTrojan:Win32/ICLoader.6a8460b8
K7GWTrojan ( 0059551b1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/S-2341b433!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAWC
CynetMalicious (score: 100)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Adrozek-9811562-0
KasperskyHEUR:Trojan.Win32.Ekstak.pef
SUPERAntiSpywareTrojan.Agent/Gen-Ekstak
AvastWin32:AdwareX-gen [Adw]
DrWebTrojan.Siggen9.22670
ZillyaTrojan.Kryptik.Win32.2034592
McAfee-GW-EditionGenericRXKR-DE!05EC50FABAAF
Trapminemalicious.high.ml.score
SophosTroj/Agent-BEQV
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.Tewgol.sotp
Antiy-AVLTrojan/Win32.Ekstak
ZoneAlarmHEUR:Trojan.Win32.Ekstak.pef
MicrosoftBrowserModifier:Win32/Adrozek
GoogleDetected
AhnLab-V3Trojan/Win32.Staser.C4102643
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36308.jv0@aGFx7bbe
VBA32BScope.Trojan.Wacatac
MalwarebytesCrypt.Trojan.Malicious.DDS
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.Kryptik!NWhnH+3Yfo4
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.74629352.susgen
FortinetW32/CoinMiner.GYQC!tr
Cybereasonmalicious.abaaf9
PandaTrj/GdSda.A

How to remove Crypt.Trojan.Malicious.DDS?

Crypt.Trojan.Malicious.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment