Trojan

Crypt.Trojan.Malicious.DDS malicious file

Malware Removal

The Crypt.Trojan.Malicious.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Crypt.Trojan.Malicious.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Crypt.Trojan.Malicious.DDS?


File Info:

name: B60B55BB902E8134E240.mlw
path: /opt/CAPEv2/storage/binaries/5f69c1d6106890c21d331c9214fcf164f15ee9789ba2a7f22460f14ef06e5ee1
crc32: 68ACB6E0
md5: b60b55bb902e8134e240c529f92aad9a
sha1: 2147025d1c63a72e7854f232addfc669538cc5a2
sha256: 5f69c1d6106890c21d331c9214fcf164f15ee9789ba2a7f22460f14ef06e5ee1
sha512: 128a63e76826f34cec6e9936b857a2affe4c0b5113fa39c78b416f57a91378a6088e3176717267771ddf17910420a567436de8f17926012e19380a0050cfbd5e
ssdeep: 12288:w2Q2ewTedA91yorjT1DOdNHh/6Uqa2/H5BdamUpbFg+OOA/3f/gBSlYqx:GDmed+1nrodgpvvdrUpzONUS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191F43365667BE1B1C97C3536665E8277A8EBEDF4A664F3B95E8DF90C03323172900220
sha3_384: 6507074a5feac3702e7d0ee3e047f211d0b3ab63dce999578f237a022d8219695ca78a1f6b0ece858394ef48adf9847c
ep_bytes: 68004040005f8d35e02f40006a1d59f3
timestamp: 2012-08-31 23:11:12

Version Info:

0: [No Data]

Crypt.Trojan.Malicious.DDS also known as:

LionicTrojan.Win32.Generic.lmka
MicroWorld-eScanTrojan.Generic.KDZ.3014
CAT-QuickHealTrojan.Lethic.B
ALYacTrojan.Generic.KDZ.3014
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPRETrojan.Generic.KDZ.3014
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
K7GWTrojan ( 0040f2c01 )
Cybereasonmalicious.b902e8
BaiduWin32.Trojan.Kryptik.ur
VirITTrojan.Win32.X-Agent.HC
CyrenW32/FakeAlert.WP.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.ARUZ
APEXMalicious
ClamAVWin.Trojan.Fakeav-19042
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Generic.KDZ.3014
NANO-AntivirusTrojan.Win32.Slym.fkkcfa
AvastWin32:FakeAlert-DCG [Trj]
RisingTrojan.Kryptik!1.A81D (CLASSIC)
EmsisoftTrojan.Generic.KDZ.3014 (B)
F-SecureTrojan.TR/Winwebsec.ioinw
DrWebBackDoor.Slym.1375
TrendMicroWORM_KELIHOS.SMB
McAfee-GW-EditionFakeAV-SecurityTool.gw
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b60b55bb902e8134
SophosMal/Zbot-KR
IkarusTrojan-PSW.Win32.Tepfer
JiangminTrojan/Tepfer.Gen
GoogleDetected
AviraTR/Winwebsec.ioinw
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
MicrosoftBackdoor:Win32/Kelihos.F
XcitiumTrojWare.Win32.Kryptik.ARLI@4t2kfq
ArcabitTrojan.Generic.KDZ.DBC6
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Generic.KDZ.3014
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R48460
Acronissuspicious
McAfeeBackDoor-FJW
VBA32Trojan.FakeAV.01657
Cylanceunsafe
TrendMicro-HouseCallWORM_KELIHOS.SMB
TencentWin32.Trojan.Generic.Kajl
YandexTrojan.Kryptik!zpVSl8y6hys
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.X!tr
BitDefenderThetaGen:NN.ZexaF.36308.UqW@aC0EG8d
AVGWin32:FakeAlert-DCG [Trj]
PandaTrj/Tepfer.B
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Crypt.Trojan.Malicious.DDS?

Crypt.Trojan.Malicious.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment