Malware

About “Win32/Kryptik.DCNW” infection

Malware Removal

The Win32/Kryptik.DCNW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DCNW virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Win32/Kryptik.DCNW?


File Info:

crc32: 5A5E03E8
md5: f3780fd4b24471eafc95a2bef13a4c00
name: F3780FD4B24471EAFC95A2BEF13A4C00.mlw
sha1: eb87ebf25448e4c3773ce3990e680c832618dc7c
sha256: 6c8991b7c7fb380d105c4c39fa39c6b188b48d3d5279d7c70b73975583795c2f
sha512: 60c845a5f8bcd51ff4e218d0deca891388872aeb49596033456b841c604bb49b6140b504eae421fa7aeebc012ac220f7c2a6bb699d4a877ae356ee09100b1076
ssdeep: 6144:rwhBEHzWpUfPNr+DRD5fWBuxBl11tbpuO:8hB2zWSdWJZRxPPF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.DCNW also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Inject1.53764
MicroWorld-eScanWin32.Doboc.Gen.1
FireEyeGeneric.mg.f3780fd4b24471ea
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Win32/Trojan.Doboc.HxQBXK8A
McAfeeTrojan-FGBQ!F3780FD4B244
CylanceUnsafe
VIPREVirus.Win32.Ursnif.ha (v)
AegisLabVirus.Win32.PolyRansom.mhJM
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040fa661 )
BitDefenderWin32.Doboc.Gen.1
K7GWTrojan ( 0040fa661 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:FileInfector.1210116D11
CyrenW32/Virus.FQFG-3191
SymantecW32.Tempedreve.E!inf
TrendMicro-HouseCallPE_URSNIF.E
AvastWin32:Malware-gen
ClamAVWin.Trojan.Doboc-292
KasperskyVirus.Win32.PolyRansom.c
NANO-AntivirusTrojan.Win32.PolyRansom.dpzfcr
ViRobotWin32.Ursnif.A
RisingTrojan.Win32.Kryptik.z (CLOUD)
Ad-AwareWin32.Doboc.Gen.1
EmsisoftWin32.Doboc.Gen.1 (B)
ComodoTrojWare.Win32.Ursnif.KIL@5jjifs
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Kryptik.iq
ZillyaVirus.PolyRansom.Win32.3
TrendMicroPE_URSNIF.E
McAfee-GW-EditionBehavesLike.Win32.DocumentCrypt.fm
SophosMal/Generic-R + W32/MPhage-B
SentinelOneStatic AI – Malicious PE
JiangminVirus.PolyRansom.ec
WebrootW32.Malware.Mlpe
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLVirus/Win32.PolyRansom.c
KingsoftWin32.Infected.AutoInfector.a.(kcloud)
MicrosoftTrojan:Win32/Ursnif.KSV!MTB
ArcabitWin32.Doboc.Gen.1
SUPERAntiSpywareRansom.Cryptor/Variant
ZoneAlarmVirus.Win32.PolyRansom.c
GDataWin32.Doboc.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ursnif.R158712
Acronissuspicious
VBA32SScope.Trojan.FakeAV.01681
ALYacWin32.Doboc.Gen.1
TACHYONTrojan/W32.Doboc
MalwarebytesPolyRansom.Virus.FileInfector.DDS
PandaW32/CryptD.C
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.DCNW
TencentTrojan.Win32.Tuscas.a
YandexTrojan.GenAsa!RK3x+npEgzs
IkarusTrojan-Ransom.Locky
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.DCNW!tr
AVGWin32:Malware-gen
Cybereasonmalicious.4b2447
Paloaltogeneric.ml
MaxSecureVirus.w32.PolyRansom.C

How to remove Win32/Kryptik.DCNW?

Win32/Kryptik.DCNW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment