Malware

How to remove “Adrozek.33”?

Malware Removal

The Adrozek.33 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adrozek.33 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Adrozek.33?


File Info:

name: CE3D5794F5E712861E48.mlw
path: /opt/CAPEv2/storage/binaries/9f828b547670ad7479977663d72bf3bc26545f23afcd7c178fe66f00280ecd87
crc32: 6702CB42
md5: ce3d5794f5e712861e481749c086af38
sha1: 733a771ff9c84778fb7b984da130cf03decbd56a
sha256: 9f828b547670ad7479977663d72bf3bc26545f23afcd7c178fe66f00280ecd87
sha512: 2ec8a05bb4dd63cfa8829406e6c2c5375ce27417b99d6e20e1fd2547856ccbcf49cc3a03ceeed3ce54ca7d2eee79d0e31ef361d4653b993cc2288b2e6b09e55e
ssdeep: 24576:p90tLgxCJ/5avFAjo6I9F5kZ8Sm+TBYU7rBRsfyHvIedknkuh7:h6UOPmaq1Oddknkuh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6759F12F2105810E3F495344437AA5D25B07EABC72D99FB5E983DE61EF2EF089A6F01
sha3_384: 0ed402f9ee91b18553ad9a71459079c4046bea91946b5bdec221cd4705c2fef759d626404630fcb2ba0042c6d8ada540
ep_bytes: 558bec6aff6858054700688ca6460064
timestamp: 2020-10-18 14:59:13

Version Info:

CompanyName: NCT Company Ltd.
FileDescription: NCTAudioRecord2 ActiveX EXE
FileVersion: 2,5,1,130
InternalName: NCTAudioRecord2 ActiveX EXE
LegalCopyright: NCT Company Ltd. Copyright 1999 - 2003
LegalTrademarks: NCT Company Ltd.
OriginalFilename: NCTAudioRecord2.EXE
ProductName: NCTAudioRecord2 ActiveX EXE
ProductVersion: 2,5,1,130
Translation: 0x0409 0x04b0

Adrozek.33 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Adrozek.33
McAfeeGenericRXMI-RY!CE3D5794F5E7
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.56130
K7AntiVirusTrojan ( 005821bc1 )
AlibabaTrojan:Win32/Ekstak.1fc432d4
K7GWTrojan ( 005821bc1 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/ICLoader.CK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHUB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Adrozek-9811562-0
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderGen:Variant.Adrozek.33
SUPERAntiSpywareTrojan.Agent/Gen-Bulz
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Ekstak.Szvh
Ad-AwareGen:Variant.Adrozek.33
SophosML/PE-A + Troj/Agent-BEQV
ComodoMalware@#16fc1afq35vaq
DrWebTrojan.Siggen9.22670
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PKS21
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftGen:Variant.Adrozek.33 (B)
IkarusPUA.ICLoader
GDataGen:Variant.Adrozek.33
JiangminTrojan.Ekstak.bmme
AviraHEUR/AGEN.1138971
Antiy-AVLTrojan/Generic.ASMalwS.30F7A74
GridinsoftRansom.Win32.Gen.sa
ViRobotTrojan.Win32.Z.Adrozek.1615872
MicrosoftBrowserModifier:Win32/Adrozek
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ekstak.C4246957
BitDefenderThetaGen:NN.ZexaCO.34062.Iv0@aKCgU6kj
ALYacGen:Variant.Adrozek.33
MAXmalware (ai score=81)
VBA32BScope.Trojan.Staser
MalwarebytesAdware.DownloadAssistant
TrendMicro-HouseCallTROJ_GEN.R002C0PKS21
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.Ekstak!1K2V4x1F6JY
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareX-gen [Adw]
Cybereasonmalicious.4f5e71
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.73555928.susgen

How to remove Adrozek.33?

Adrozek.33 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment