Malware

Win32:Krepper-D removal guide

Malware Removal

The Win32:Krepper-D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Krepper-D virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32:Krepper-D?


File Info:

name: 53C6E0B88AAF86B4CD40.mlw
path: /opt/CAPEv2/storage/binaries/26a01143c4ccbfb409112552151f6ad249b50fc5e68fc5257a01a5e8aa9c3c68
crc32: 67281A87
md5: 53c6e0b88aaf86b4cd407b4f5a9c538c
sha1: 90f38f5f3626d7df8423d478deae1a4ba2478b19
sha256: 26a01143c4ccbfb409112552151f6ad249b50fc5e68fc5257a01a5e8aa9c3c68
sha512: 94d5937323fe1836de69af54fc80a72ca8e3349344d4351e0e86253c3adc7d5fe8db134f5f22ecb73044be613c776547cf03331feeb87b8480325c40c218542a
ssdeep: 1536:4cmjhDD3sPoudLwH/hUmxhyL11YuDEm1lSa47fMo6jaY3gbMwZA3gJqiI+vZDmh:4fN0LwH/hUmnWIuDxUa47fMo6T3hp3Q4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C93CF2222E54826F0F71A7046BBA764233D7C525F35A2EF1A9076DF4D326D0D930F69
sha3_384: 5e65beda3f93c99a586b92bd6748922ad5fbaf298a38ae2f292c3e79647bbc93451fc63d6978b05e1b97a7c758f244c3
ep_bytes: 60e8000000005883e83d508db800b0fc
timestamp: 2003-09-28 00:37:23

Version Info:

0: [No Data]

Win32:Krepper-D also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Krepper.l3gW
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Win32.Sality.RA
FireEyeGeneric.mg.53c6e0b88aaf86b4
CAT-QuickHealW32.Sality.F
SkyhighBehavesLike.Win32.Generic.nc
McAfeeW32/Sality.i.gen
Cylanceunsafe
ZillyaVirus.Krepper.Win32.3
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 000e341a1 )
AlibabaVirus:Win32/Krepper.9ccf324d
K7GWVirus ( 000e341a1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWin32.Sality.F
SymantecW32.Sality
tehtrisGeneric.Malware
ESET-NOD32Win32/Sality.H
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Kreepper-1
KasperskyVirus.Win32.Krepper.30760
BitDefenderDropped:Win32.Sality.RA
NANO-AntivirusVirus.Win32.Krepper.getc
AvastWin32:Krepper-D
TencentVirus.Win32.Krepper.a
SophosML/PE-A
F-SecureMalware.W32/Krepper.30761
DrWebWin32.HLLP.Sector.30760
VIPREDropped:Win32.Sality.RA
TrendMicroPE_SALITY.L
Trapminemalicious.high.ml.score
EmsisoftDropped:Win32.Sality.RA (B)
SentinelOneStatic AI – Malicious PE
GDataDropped:Win32.Sality.RA
JiangminWin32/Krepper.a
WebrootW32.Krepper.Gen
VaristW32/Krepper.WYNG-6962
AviraW32/Krepper.30761
Antiy-AVLVirus/Win32.Krepper.btnc
KingsoftWin32.Krepper.a.30760
XcitiumVirus.Win32.Krepper.30760@14400g
ArcabitWin32.Sality.RA
ZoneAlarmVirus.Win32.Krepper.30760
MicrosoftVirus:Win32/Krepper.30760
GoogleDetected
AhnLab-V3Win32/Sality.O
ALYacDropped:Win32.Sality.RA
MAXmalware (ai score=100)
VBA32Virus.Win32.Krepper.30760
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_SALITY.L
RisingWin32.Krepper.a (CLASSIC)
YandexTrojan.GenAsa!dUDSOmJHLTo
IkarusVirus.Win32.Krepper
MaxSecureVirus.W32.Krepper.30760
FortinetW32/Sality.AC
AVGWin32:Krepper-D

How to remove Win32:Krepper-D?

Win32:Krepper-D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment