Backdoor

Backdoor:Win32/Oztratz.B removal

Malware Removal

The Backdoor:Win32/Oztratz.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Oztratz.B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Portuguese
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Oztratz.B?


File Info:

crc32: 1A5AB3FF
md5: b4c9b6d3f600a4c3a5a88e7ba24467f3
name: B4C9B6D3F600A4C3A5A88E7BA24467F3.mlw
sha1: 41af4481b2b4b11a1bf56f30be3011038290db85
sha256: 922dd9f95bc46980f54a748a815b4ed7e263ce147910f6d9bd73f0946906bcae
sha512: a16a74a2fa55ec26c75e6a2104d37da570675531eebc0a42ea376a368ce38af44d5839a62a917050f3e9f9b56d4aec10a0cc4836c538c62dd0a200bf8f14504b
ssdeep: 6144:C7RKk/SukT7ovfiE8r+JHsDCam4Ldpmur1:YX/Rm7MdvACaOur1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

eUp Software: Hx10x01FileDescription
Comments: @x10x01CompanyName
eUp Utilities 2014: @x0ex01ProductVersion
yright xa9 AVG Netherlands B. V. 2011: Lx12x01LegalTrademarks
eUp Utilitiesx2122: Lx16x01ProductName
eUp Undelete: <x0ex01FileVersion
0.1000.340: D
Translation: 0x0407 0x04b0

Backdoor:Win32/Oztratz.B also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Cerber.1
CylanceUnsafe
ZillyaTrojan.Vucha.Win32.128
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Oztratz.fd82c9dd
K7GWTrojan ( 005224381 )
K7AntiVirusTrojan ( 005224381 )
BaiduWin32.Trojan.Kryptik.alb
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/GenKryptik.AZX
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Vucha.dc
BitDefenderTrojan.Ransom.Cerber.1
NANO-AntivirusTrojan.Win32.Vucha.evisdw
MicroWorld-eScanTrojan.Ransom.Cerber.1
TencentWin32.Trojan.Generic.Pgmr
Ad-AwareTrojan.Ransom.Cerber.1
SophosMal/Generic-R + Mal/EncPk-APV
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaAI:Packer.6FCE5D1220
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroRansom_CERBER.SMEJ5
McAfee-GW-EditionBehavesLike.Win32.PUPXCT.cm
FireEyeGeneric.mg.b4c9b6d3f600a4c3
EmsisoftTrojan.Ransom.Cerber.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Vucha.lt
AviraHEUR/AGEN.1129194
MicrosoftBackdoor:Win32/Oztratz.B
ArcabitTrojan.Ransom.Cerber.1
AegisLabTrojan.Win32.Vucha.4!c
GDataTrojan.Ransom.Cerber.1
AhnLab-V3Trojan/Win32.RL_Cerber.R330510
Acronissuspicious
McAfeeRansomware-GCQ!B4C9B6D3F600
MAXmalware (ai score=100)
VBA32BScope.TrojanDownloader.Troxen
MalwarebytesMalware.AI.2900043248
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.SMEJ5
RisingBackdoor.Vawtrak!1.AEEC (CLOUD)
YandexTrojan.GenAsa!GLHkoqzvJHc
IkarusTrojan-Spy.Win32.Ursnif
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FQRH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQB8ekA

How to remove Backdoor:Win32/Oztratz.B?

Backdoor:Win32/Oztratz.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment