Malware

Troj/Krypt-ADH (file analysis)

Malware Removal

The Troj/Krypt-ADH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Krypt-ADH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Troj/Krypt-ADH?


File Info:

name: D14471BFE7A9F2D0EC06.mlw
path: /opt/CAPEv2/storage/binaries/bd67613e316d7b33983890778f7b54b01bf7729f1a2c8561057ba370283bd6f6
crc32: E744254A
md5: d14471bfe7a9f2d0ec06aabf0df7222b
sha1: d8311042224ca1a4a43633846a4f35c4f784acd2
sha256: bd67613e316d7b33983890778f7b54b01bf7729f1a2c8561057ba370283bd6f6
sha512: 1880cd57548829bc94bca29c6b6d4475d33a587ae22998013f471fb8421f15702f84009ce6d8f1da634ac93d37df9c97156b921031451feddd15826bf24a0cc3
ssdeep: 1536:SkF8AF6IzC7eoA7nNpGPIP9yTgoW6k8iEgIlf9gjgaEnz57/eXC9eXkoFegdu8d2:SfCtLJ4TW6kzmAgaE5qy9Potdn2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0E3BE2236E0C471E0E7593058B486B01EBBBC532770529F27A4377F6EA22D48E757A7
sha3_384: a5920c95335ee80a7739ac42b226334aa0897bcaeb3daab5f6a658bf91edb47d7f577c1b676d85b400bec5354f92c54e
ep_bytes: e8571a0000e989feffff8bff558bec81
timestamp: 2022-09-16 03:20:06

Version Info:

FileVersions: 72.15.26.32
ProductVersion: 94.12.70.36
InternalName: Slupido
CompanyNames: Laying
Translation: 0x146c 0x0235

Troj/Krypt-ADH also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.d14471bfe7a9f2d0
SkyhighBehavesLike.Win32.PUPXAC.cm
McAfeeArtemis!D14471BFE7A9
MalwarebytesGeneric.Malware/Suspicious
SangforRansom.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.jq0@aKPGBWu
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
AvastPWSX-gen [Trj]
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ADH
SentinelOneStatic AI – Suspicious PE
GoogleDetected
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
Cylanceunsafe
RisingTrojan.Generic@AI.98 (RDML:+gFrY2YXlDPTK1lPYzX2bw)
IkarusTrojan.Win32.Glupteba
FortinetW32/GenKryptik.DPXA!tr
AVGPWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Troj/Krypt-ADH?

Troj/Krypt-ADH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment