Malware

Win32/Kryptik.DNCM malicious file

Malware Removal

The Win32/Kryptik.DNCM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DNCM virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Romanian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Looks up the external IP address
  • Creates a slightly modified copy of itself

Related domains:

icanhazip.com

How to determine Win32/Kryptik.DNCM?


File Info:

crc32: 1DF2EAB0
md5: 8ea9aaa541eddff6e838dd07d7ebcab3
name: 8EA9AAA541EDDFF6E838DD07D7EBCAB3.mlw
sha1: 54e03d9f2311fccdf8b06ddb5fae363ba0dc376e
sha256: 3ae504e2f703ac86caf8ef8a2d4f13dd852832912c82cb5c140b3196657bf80e
sha512: 8d061eb7f040e3984fdae56f7c76ebb77b8fd7d775fabb775b53acf1daec8cd451d571c50681e0161d178c78d2c88aa12a1056d87fffd61e1111a3cfde857b22
ssdeep: 384:I/U6Ur8rRP1LbIRVl7tIWh0mjcllYSNWJUwCipQ9cEQeRS+D6em2Qj1+9ulSwx:f6Ur++PGW5gllYSNW2F6Q95V/dZu8wx
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
InternalName:
FileVersion: 2.3.0.104
CompanyName: RETRO-soft
LegalTrademarks:
ProductName: RETROTool
ProductVersion: 2.3
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Win32/Kryptik.DNCM also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader14.1017
ClamAVWin.Packed.Upatre-9771589-0
CAT-QuickHealTrojanAPT.LecnaCShip.MUE.Z4
ALYacGen:Variant.Jaike.5306
CylanceUnsafe
ZillyaDownloader.UpatreGen.Win32.66
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 004c75411 )
K7AntiVirusTrojan ( 004c75411 )
BaiduWin32.Trojan.Kryptik.jq
SymantecDownloader.Upatre
ESET-NOD32a variant of Win32/Kryptik.DNCM
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Jaike.5306
NANO-AntivirusTrojan.Win32.Upatre.duaakk
MicroWorld-eScanGen:Variant.Jaike.5306
TencentMalware.Win32.Gencirc.114d9a09
Ad-AwareGen:Variant.Jaike.5306
SophosML/PE-A + Mal/Upatre-S
ComodoTrojWare.Win32.TrojanDownloader.Waski.FSA@5su3z8
BitDefenderThetaGen:NN.ZexaF.34170.cmLfa8oyj!oG
TrendMicroTROJ_UPATRE.SMHI
McAfee-GW-EditionBehavesLike.Win32.Backdoor.nh
FireEyeGeneric.mg.8ea9aaa541eddff6
EmsisoftGen:Variant.Jaike.5306 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bgpui
AviraHEUR/AGEN.1125852
eGambitUnsafe.AI_Score_90%
Antiy-AVLTrojan/Generic.ASMalwS.129161A
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan-Downloader.Upatre.BK
AhnLab-V3Trojan/Win.Generic.R443871
McAfeeUpatre-FACH!4E65405C6EBE
MAXmalware (ai score=84)
VBA32BScope.Trojan.Downloader
MalwarebytesTrojan.Upatre.Generic
TrendMicro-HouseCallTROJ_UPATRE.SMHI
RisingMalware.FakePDF/ICON!1.A24C (CLASSIC)
YandexTrojan.GenAsa!7Fved79bRSY
IkarusTrojan.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.DNCM!tr
AVGWin32:Trojan-gen

How to remove Win32/Kryptik.DNCM?

Win32/Kryptik.DNCM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment