Malware

Adrozek.38 removal guide

Malware Removal

The Adrozek.38 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adrozek.38 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself

How to determine Adrozek.38?


File Info:

name: D90949419D133C7D0828.mlw
path: /opt/CAPEv2/storage/binaries/5a6f21fe76ae09c7595a30d59459a88fabee5a0c5a4e2d2121863b7be60b26bc
crc32: 1984278C
md5: d90949419d133c7d08289a0f4b1c964b
sha1: d8c67320828473f65238dcf793f1cd0332361b6c
sha256: 5a6f21fe76ae09c7595a30d59459a88fabee5a0c5a4e2d2121863b7be60b26bc
sha512: 94f48e3cda19f4da5cf9104294029b5301a739f84491c2894838f2540cd312f183477fabc89ba6285736864a669efe7ae9fdfd2ccf9186108b71a60ed8d95bfa
ssdeep: 49152:nnsUYDgPoc/jYdqWpSfzoZmyamMCgp4dZOv4i:nnZYD5c/jYUWE7Smydm4dZOvX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161B5012373A00077D1F18E788E37FDE57676AE62AE019C39A5E8ADC819255D0F213397
sha3_384: ec655060aea5bf7c3d84219fd593b0cde55f0bee1ec5217ee70b70535d65e425fcfddba228538c55b84151e9bd56013e
ep_bytes: 558bec6aff68a8c6570068c0b6570064
timestamp: 2020-10-10 19:52:01

Version Info:

0: [No Data]

Adrozek.38 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Razy.a!c
tehtrisGeneric.Malware
DrWebTrojan.PWS.Stealer.29366
MicroWorld-eScanGen:Variant.Adrozek.38
FireEyeGeneric.mg.d90949419d133c7d
McAfeeArtemis!D90949419D13
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 0058214e1 )
AlibabaTrojanDownloader:Win32/Kryptik.17424b07
K7GWTrojan ( 0058214e1 )
Cybereasonmalicious.19d133
BitDefenderThetaGen:NN.ZexaF.34742.uAW@a060JNck
CyrenW32/FakeAlert.FY.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HAYM
TrendMicro-HouseCallTROJ_GEN.R002C0RFE22
Paloaltogeneric.ml
ClamAVWin.Packed.Adrozek-9811562-0
KasperskyHEUR:Trojan-Downloader.Win32.Razy.gen
BitDefenderGen:Variant.Adrozek.38
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan-downloader.Razy.Wpsz
Ad-AwareGen:Variant.Adrozek.38
SophosML/PE-A + Troj/Agent-BEQV
TrendMicroTROJ_GEN.R002C0RFE22
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Adrozek.38 (B)
IkarusTrojan.Crypt.Agent
JiangminTrojanDownloader.Razy.hci
AviraTR/AD.CrthRazy.bce
MicrosoftBrowserModifier:Win32/Adrozek
GDataGen:Variant.Adrozek.38
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Wacatac.R358619
Acronissuspicious
VBA32BScope.Trojan.CryptInject
ALYacGen:Variant.Adrozek.38
MalwarebytesAdware.DownloadAssistant
APEXMalicious
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.Kryptik!yJN3Konxwv0
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HASW!tr
AVGWin32:AdwareX-gen [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Adrozek.38?

Adrozek.38 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment