Trojan

Trojan.Win32.Cryprar.uw (file analysis)

Malware Removal

The Trojan.Win32.Cryprar.uw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.uw virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.uw?


File Info:

name: 011E0BAE268A75C3AC79.mlw
path: /opt/CAPEv2/storage/binaries/ef483f879c41825d3a4b79c4cbc0570a78852eeaea3329c02970d80d94044d7e
crc32: AD9D14AB
md5: 011e0bae268a75c3ac79c15d5ca2bbdb
sha1: b8537ff0ff2225c883acea6b1bc8099d517c942c
sha256: ef483f879c41825d3a4b79c4cbc0570a78852eeaea3329c02970d80d94044d7e
sha512: ae5ad24647c3789af5beb202f8b723917f43f78d0ee2facc08a31904132b53266d831c4ed663f1c8e4b8fef18709b31c9c89bba106a513ecfed136fae896e4e9
ssdeep: 24576:/cypUTkBfJXAEND2YJRlWeBrDHP1LHas4hRYv9:3rBfJXAE/JBDdLHH4El
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154451202FED144B2D4B20E311A79A7655DBE78600F10DADFE3A45CAE9F311C16A3A763
sha3_384: 9f5f26482ae601aff767da21121fb468a68f7e74ea47df6f7641b93095d8587f9be20076583f573877cdb04edd802a02
ep_bytes: e894040000e988feffff3b0d18d54300
timestamp: 2021-06-11 09:17:01

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 6.2.0
ProductVersion: 6.2.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2021
OriginalFilename: WinRAR.exe
Translation: 0x0409 0x04e4

Trojan.Win32.Cryprar.uw also known as:

DrWebTrojan.MulDrop19.8331
MicroWorld-eScanTrojan.GenericKD.38137242
FireEyeTrojan.GenericKD.38137242
McAfeeArtemis!011E0BAE268A
AlibabaTrojan:Win32/Cryprar.f02bbf00
K7GWTrojan ( 0057bde51 )
K7AntiVirusTrojan ( 0057bde51 )
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DJ
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0DKR21
KasperskyTrojan.Win32.Cryprar.uw
BitDefenderTrojan.GenericKD.38137242
AvastSFX:Runner-C [Bd]
Ad-AwareTrojan.GenericKD.38137242
EmsisoftTrojan.GenericKD.38137242 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
SophosMal/Generic-S
IkarusTrojan.Agent
GDataTrojan.GenericKD.38137242
JiangminTrojan.Generic.haxnr
AviraTR/Agent.kybyk
GridinsoftRansom.Win32.Wacatac.sa
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
VBA32Trojan.Swrort
ALYacTrojan.GenericKD.38137242
MAXmalware (ai score=84)
MalwarebytesTrojan.Dropper.VBS
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
AVGSFX:Runner-C [Bd]
PandaTrj/CI.A

How to remove Trojan.Win32.Cryprar.uw?

Trojan.Win32.Cryprar.uw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment