Trojan

About “Trojan.Win32.Cryprar.tz” infection

Malware Removal

The Trojan.Win32.Cryprar.tz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.tz virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.tz?


File Info:

name: 238B93460820A01A4B2A.mlw
path: /opt/CAPEv2/storage/binaries/af964df09a90924dec23bc5a94d5efdcc839b4eb2e2d44064f7fb6378b21d15e
crc32: 649D1AE3
md5: 238b93460820a01a4b2abd133494d4e2
sha1: e4419934e02c7d42a3b6c08d75ba5e24a13dc295
sha256: af964df09a90924dec23bc5a94d5efdcc839b4eb2e2d44064f7fb6378b21d15e
sha512: b08b9c8af13f2c867267677722db158153f7cb94ce9f69ced92ac6d174d9a4bec97ff76bef51410e5d747c5e335c17e10220760531fb8f69b70021ed7894dc96
ssdeep: 49152:8UBfJXAEmykuL4folIORt9mqpkWrEmcoAyHpp7:8UBfKESucfolIssdmcoAyHD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1752302F9DA9472C4B319354E2A6791AD3B7C704FB4C68F73A858ADAB312C17634763
sha3_384: 6c33000b33d967ec3412e0c741a71ffea69e31e5a86f63d6c37e40f707cb8a93935a417f8829467ffa3da0bc89d3185d
ep_bytes: e8d4040000e988feffff3b0d18d54300
timestamp: 2021-03-05 21:34:29

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 6.1.1
ProductVersion: 6.1.1
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2021
OriginalFilename: WinRAR.exe
Translation: 0x0409 0x04e4

Trojan.Win32.Cryprar.tz also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Ciusky.4!c
MicroWorld-eScanTrojan.Ciusky.Gen.6
FireEyeTrojan.Ciusky.Gen.6
McAfeeArtemis!238B93460820
K7AntiVirusTrojan ( 0057bde51 )
AlibabaTrojan:Win32/Cryprar.cbf33571
K7GWTrojan ( 0057bde51 )
Cybereasonmalicious.60820a
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DJ
AvastSFX:Runner-C [Bd]
KasperskyTrojan.Win32.Cryprar.tz
BitDefenderTrojan.Ciusky.Gen.6
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
Ad-AwareTrojan.Ciusky.Gen.6
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.Ciusky.Gen.6 (B)
Paloaltogeneric.ml
AviraTR/Agent.pnhmr
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Woreflint.A!cl
GDataWin32.Trojan.Kryptik.C15YXI
CynetMalicious (score: 99)
ALYacTrojan.Ciusky.Gen.6
VBA32Trojan.Shelma
MalwarebytesTrojan.Dropper
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0DKP21
AVGSFX:Runner-C [Bd]
PandaTrj/CI.A

How to remove Trojan.Win32.Cryprar.tz?

Trojan.Win32.Cryprar.tz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment