Malware

Win32/Kryptik.LDS removal instruction

Malware Removal

The Win32/Kryptik.LDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.LDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

How to determine Win32/Kryptik.LDS?


File Info:

name: 8BBA1FDE65D37D3EEC78.mlw
path: /opt/CAPEv2/storage/binaries/55c2ac04d3346c4644f3ddf2659db9d0182397a8c4105a9017422a53b70db478
crc32: 0BA3EC41
md5: 8bba1fde65d37d3eec7847e2c92270fe
sha1: a910c1093704274d42f7b84372612c36f9eb0333
sha256: 55c2ac04d3346c4644f3ddf2659db9d0182397a8c4105a9017422a53b70db478
sha512: a4888398e1557f55bcbd0159b3fad0722a106f995258271ff51081d16682029b4d4c2f3f1f6435696997937041b18b415ac25ed70d2a9d4f00fac89d98f80e39
ssdeep: 12288:05mQ7jA+nFAY0Y4oj6thYk6ZFsSXijvGZlgV13:05vChY4M6uZmMirkuV1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180940216F29794AAD7FB5B3699119B23AF31F96C562019006B812E8FAD3F343076F341
sha3_384: e385f6e6e862d56e0a04ac49ecad7d6f570e0b2831a330fc2fe378dda727c6052b679cde7f3580fd2bcdec05a49533f5
ep_bytes: 55f7d603de8bf88bec4003c2f7d283c4
timestamp: 2004-12-09 21:12:30

Version Info:

0: [No Data]

Win32/Kryptik.LDS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Gimemo.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.49604
McAfeeArtemis!8BBA1FDE65D3
MalwarebytesMalware.Heuristic.1006
SangforTrojan.Win32.Kryptik.LDS
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderGen:Variant.Razy.49604
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.e65d37
VirITTrojan.Win32.Winlock.EME
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LDS
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Gimemo.vc
AlibabaRansom:Win32/Gimemo.d98d5ebc
NANO-AntivirusTrojan.Win32.Gimemo.bwsfv
ViRobotTrojan.Win32.A.Gimemo.363008.A
AvastWin32:MalOb-FT [Cryp]
RisingRansom.Gimemo!8.306 (CLOUD)
Ad-AwareGen:Variant.Razy.49604
EmsisoftGen:Variant.Razy.49604 (B)
ComodoMalware@#2whr3ko1bu4yt
F-SecureHeuristic.HEUR/AGEN.1223592
DrWebTrojan.Winlock.3020
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroTROJ_CRYPTR.SMKV
McAfee-GW-EditionBehavesLike.Win32.Dropper.gh
FireEyeGeneric.mg.8bba1fde65d37d3e
SophosMal/Generic-R + Mal/EncPk-OJ
GDataGen:Variant.Razy.49604
JiangminTrojan/Gimemo.hj
AviraHEUR/AGEN.1223592
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
ArcabitTrojan.Razy.DC1C4
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmTrojan-Ransom.Win32.Gimemo.vc
MicrosoftRansom:Win32/LockScreen.AO
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R2835
VBA32Trojan.Zeus.EA.0999
ALYacGen:Variant.Razy.49604
CylanceUnsafe
TrendMicro-HouseCallTROJ_CRYPTR.SMKV
TencentWin32.Trojan.Gimemo.Edxy
YandexTrojan.GenAsa!7g+izay46Vg
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
BitDefenderThetaGen:NN.ZexaF.34212.ACW@a4Du05jc
AVGWin32:MalOb-FT [Cryp]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.LDS?

Win32/Kryptik.LDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment