Malware

Win32/Kryptik.DCT (file analysis)

Malware Removal

The Win32/Kryptik.DCT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DCT virus can do?

  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.DCT?


File Info:

name: 7D5D4A0D4256514828E6.mlw
path: /opt/CAPEv2/storage/binaries/72eaf3d96a6502285d32344c5bc8a8e387431c9c784feb2d3bcc32e5c224bdb0
crc32: F4A9FD66
md5: 7d5d4a0d4256514828e6e192c96c30c7
sha1: a650c9bc5d6b4b15583b10d28e003312b1670a18
sha256: 72eaf3d96a6502285d32344c5bc8a8e387431c9c784feb2d3bcc32e5c224bdb0
sha512: 395e6a898551ca4d027235ea6d2158211c5baf71d56c16b4337f066cd62d98201c37e4d9dc568268c9ce38f712938f46a9c90cf3258f044e68f28815fe937c26
ssdeep: 3072:MnmR0FeM13hflgxvG5jIM7xZCIj3vXxRNRKuEbzM/D9MLqhtamidPky8JtT:L0f3pQ3OLCu/AzID9KqhAlD8J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132E3F191EB11C155F1948570CC350BE0273A6C57EC32B94B52A07F8DBAF2782963B9AF
sha3_384: 792da4f21f17b981fac8ec6dd4ee97538bdf37e36d4b3c8908f07c77f3b750224620d795f75c133b27eec5b094a2967f
ep_bytes: 60be007043008dbe00a0fcff5783cdff
timestamp: 2009-04-28 05:21:35

Version Info:

CompanyName: Ey4gJ,Ifk
FileDescription: ZI575wMDw
FileVersion: NAJ4scZQu
InternalName: raP4X4k.g
LegalCopyright: X2qNtHrUy
OriginalFilename: 5Sgk28QS6
ProductName: Y9k4OnDkw
ProductVersion: eFLzPH5Aw
Translation: 0x0000 0x0000

Win32/Kryptik.DCT also known as:

LionicWorm.Win32.Palevo.li7b
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Krypt.24
FireEyeGeneric.mg.7d5d4a0d42565148
CAT-QuickHealWorm.Silly
SkyhighBehavesLike.Win32.Generic.cc
ZillyaWorm.Palevo.Win32.113922
K7AntiVirusTrojan ( 0040f7aa1 )
AlibabaWorm:Win32/Rimecud.4725ec45
K7GWTrojan ( 0040f7aa1 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Krypt.24
BitDefenderThetaAI:Packer.E7BA629C1F
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.DCT
CynetMalicious (score: 100)
ClamAVWin.Trojan.Ag-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Krypt.24
NANO-AntivirusTrojan.Win32.Crypted.ctlxxm
AvastWin32:Crumpache [Cryp]
TencentWin32.Trojan.Generic.Kqil
EmsisoftGen:Heur.Krypt.24 (B)
F-SecureWorm:W32/Palevo.BT
DrWebTrojan.Packed.20312
VIPREGen:Heur.Krypt.24
TrendMicroWORM_PALEVO.SMJJ
SophosMal/Zbot-EZ
IkarusP2P-Worm.Win32.Palevo
JiangminTrojan/Generic.aodhn
VaristW32/Rimecud.I.gen!Eldorado
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.HeurC.KVM007.a
XcitiumMalCrypt.Indus!@1qrzi1
MicrosoftTrojan:Win32/Ditertag.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Krypt.24
GoogleDetected
AhnLab-V3Win32/Palevo4.worm.Gen
McAfeeArtemis!7D5D4A0D4256
VBA32BScope.Trojan.MTA.0230
Cylanceunsafe
PandaTrj/Rimecud.a
TrendMicro-HouseCallWORM_PALEVO.SMJJ
RisingMalware.FakePIC/ICON!1.6AB7 (CLASSIC)
YandexWorm.Palevo.Gen!Pac.6
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.ANQ!tr
AVGWin32:Crumpache [Cryp]
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.DCT?

Win32/Kryptik.DCT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment