Malware

About “Win32:KdCrypt [Cryp]” infection

Malware Removal

The Win32:KdCrypt [Cryp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:KdCrypt [Cryp] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:KdCrypt [Cryp]?


File Info:

name: 1C9B778FCB39E7E3246E.mlw
path: /opt/CAPEv2/storage/binaries/159df5b4715f279ea54374b9594d7e406fbe2cf5fd9a8c19a8a25a2d05187dfd
crc32: E61D89D9
md5: 1c9b778fcb39e7e3246e907572f893ad
sha1: e84f80c70dc94e6501575735d662805eb4b675a7
sha256: 159df5b4715f279ea54374b9594d7e406fbe2cf5fd9a8c19a8a25a2d05187dfd
sha512: d7c343bfb994b1c9c77c1594a7369fc92b4e9874cc2409c50e27449c3011f69859dfe0f8a6eec1c975b3964f155fd87a9b6ca378c7aaace204069289c5b69a2b
ssdeep: 1536:DxgZyukil2TqQ18ZnvspqwWK8Y4eMXVh:Dxk/Mzw3wWKhXMX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A33F1C344845262E206347A23C674FDBECAFC22EB6E87E792500320E935CDD71D9369
sha3_384: 816890d1ffccc7cb0f8e5c4a087747334418e3ac2f26b564f4229b51ba279aaf279577d972c0c476e3b78522b074010b
ep_bytes: 572bbc24a9ffffff5f668cc832c00ae4
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Win32:KdCrypt [Cryp] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Scar.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Inject.HW
FireEyeGeneric.mg.1c9b778fcb39e7e3
SkyhighBehavesLike.Win32.DNSChanger.qc
McAfeeDNSChanger.gen.a
Cylanceunsafe
ZillyaTrojan.Scar.Win32.16318
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f10004011 )
AlibabaTrojanDownloader:Win32/Medfos.f65e4146
K7GWTrojan ( f10004011 )
Cybereasonmalicious.fcb39e
BitDefenderThetaAI:Packer.0052D7371E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Zlob.BXN
APEXMalicious
TrendMicro-HouseCallMal_Zlob-16
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Inject.HW
NANO-AntivirusTrojan.Win32.Scar.toqof
AvastWin32:KdCrypt [Cryp]
TencentWin32.Trojan.Generic.Ljgl
EmsisoftTrojan.Inject.HW (B)
F-SecureTrojan.TR/Vundo.Gen
DrWebTrojan.Packed.196
VIPRETrojan.Inject.HW
TrendMicroMal_Zlob-16
Trapminemalicious.high.ml.score
SophosMal/Mdrop-I
IkarusTrojan-Downloader.Win32.Zlob
JiangminTrojan/Monder.Gen.a
GoogleDetected
AviraTR/Vundo.Gen
VaristW32/Virtumonde.T.gen!Eldorado
KingsoftWin32.Troj.DNSChangerT.dx.14848
MicrosoftTrojan:Win32/Alureon.gen
XcitiumTrojWare.Win32.Trojan.DNSChanger.~CRSB@1qelwn
ArcabitTrojan.Inject.HW
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Inject.HW
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Monder.C72152
VBA32BScope.Trojan.Packed
ALYacTrojan.Inject.HW
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.2046
PandaTrj/Genetic.gen
RisingTrojan.Win32.DNSChanger.drb (CLASSIC)
YandexTrojan.Vundo.Gen!Pac.38
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Monder.GEN
FortinetW32/Monder.XCF!tr
AVGWin32:KdCrypt [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[downloader]:Win/Zlob.BXN

How to remove Win32:KdCrypt [Cryp]?

Win32:KdCrypt [Cryp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment