Malware

Adrozek.76 (file analysis)

Malware Removal

The Adrozek.76 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adrozek.76 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Adrozek.76?


File Info:

crc32: 594A3194
md5: fbb9fee2625e181c42879b46d1f476af
name: FBB9FEE2625E181C42879B46D1F476AF.mlw
sha1: 32c93664161252630fe4afdf6f06a8db06ab643c
sha256: 3e5d979800e23d09c94bc898fbd21f53995fdc1e55309a6c0a55e02d2441a89c
sha512: 870f9a6291aba9316c5f672a0a531d47296852f9e1284380f91aeb62dc06bb3c8636d10077090da3ee78b75034cd44789d72df4869d6bfac3dc1df30462343e3
ssdeep: 12288:ZVyWMGer8SF37ssKSShGMurVTqSkE1jnqGnhQvsnWSDKf8v22PdoI6ZSd9chppq:PSZoJur8SkEVB5NKfa221n629chiNaA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2013 WIDISOFT
InternalName: WIDI
FileVersion: 4.3.1580
CompanyName: WIDISOFT
LegalTrademarks1: All Rights Reserved
LegalTrademarks2: All Rights Reserved
ProductName: WIDI Recognition System
ProductVersion: 4.3
FileDescription: WIDI Recognition System
OriginalFilename: Widi.exe
Translation: 0x0409 0x04e4

Adrozek.76 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0058214e1 )
LionicTrojan.Win32.Staser.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.22670
CynetMalicious (score: 100)
ALYacGen:Variant.Adrozek.76
CylanceUnsafe
ZillyaTrojan.Staser.Win32.9927
SangforAdware.Win32.Adrozek.mt
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Staser.cea77aa5
K7GWTrojan ( 0058214e1 )
Cybereasonmalicious.2625e1
CyrenW32/Ekstak.Y.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHUB
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Packed.Zusy-9777681-0
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Adrozek.76
NANO-AntivirusTrojan.Win32.Staser.hzotib
MicroWorld-eScanGen:Variant.Adrozek.76
TencentWin32.Trojan.Staser.Egof
Ad-AwareGen:Variant.Adrozek.76
SophosTroj/Agent-BEQV
ComodoMalware@#2cf2wirhetodi
BitDefenderThetaGen:NN.ZexaCO.34266.mv0@aypiwABT
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Tupym.tc
FireEyeGeneric.mg.fbb9fee2625e181c
EmsisoftGen:Variant.Adrozek.76 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Staser.gej
AviraTR/Crypt.Agent.wjdyh
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.30F313B
MicrosoftBrowserModifier:Win32/Adrozek
ArcabitTrojan.Adrozek.76
SUPERAntiSpywareTrojan.Agent/Gen-Staser
GDataGen:Variant.Adrozek.76
AhnLab-V3PUP/Win32.FakeInstaller.C4205354
Acronissuspicious
McAfeeGenericRXMG-FR!FBB9FEE2625E
MAXmalware (ai score=83)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.DownloadAssistant
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Adrozek.76?

Adrozek.76 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment