Malware

Troj/Kryptik-ZR removal instruction

Malware Removal

The Troj/Kryptik-ZR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Kryptik-ZR virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Troj/Kryptik-ZR?


File Info:

crc32: 7D06970B
md5: 7576d0cf0b60965127fbe253a599c2ac
name: 7576D0CF0B60965127FBE253A599C2AC.mlw
sha1: 6823fff1d48aac4f2da4ced06c84d8a7d44a348e
sha256: a8a459f4d2976c7aca51862d982dd146eaee35f19d6e434d7224cbfdad6665cd
sha512: a479ff4ed07b817b60ce42e27b3ce3b6ff4b095b8ad979a2c7a9e41a7252cd020b81264e8be6a502cbaec689aa1299349c6feea29705b163f3757f204f66b801
ssdeep: 12288:nmMrvgzj/pg0QpuuMTM6W3aBaWJiOZlwlkzM8I33xSCPmRn1XN5GnTOdU+CHpZg:bvmj/pg3pmC3aBaiirUM1xSdDv
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014 - 2021
Assembly Version: 9.2.0.3
InternalName: IActivationFacto.exe
FileVersion: 9.2.0.3
CompanyName: MicroStar
LegalTrademarks:
Comments:
ProductName: Probability Engine
ProductVersion: 9.2.0.3
FileDescription: Probability Engine
OriginalFilename: IActivationFacto.exe

Troj/Kryptik-ZR also known as:

LionicTrojan.MSIL.NanoBot.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.924
ALYacTrojan.GenericKD.46621498
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:MSIL/AgentTesla.05d09f91
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/MSIL_Kryptik.EUC.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ABXY
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
BitDefenderTrojan.GenericKD.46621498
NANO-AntivirusTrojan.Win32.NanoBot.ixtrxw
MicroWorld-eScanTrojan.GenericKD.46621498
TencentMsil.Backdoor.Nanobot.Ahes
Ad-AwareTrojan.GenericKD.46621498
SophosTroj/Kryptik-ZR
BitDefenderThetaGen:NN.ZemsilF.34058.8m0@ae9pp7m
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R023C0DGG21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.7576d0cf0b609651
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.etyx
WebrootW32.Trojan.Gen
AviraTR/AD.AgentTesla.ofgxw
MicrosoftTrojan:MSIL/AgentTesla.CAI!MTB
GDataMSIL.Trojan.BSE.1NYDJC8
AhnLab-V3Trojan/Win.PWSX-gen.C4551431
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R023C0DGG21
YandexTrojan.Kryptik!VlZK8fwcbR4
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.AgentTesla.HwMAkOUA

How to remove Troj/Kryptik-ZR?

Troj/Kryptik-ZR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment