Trojan

Should I remove “Trojan.Win32.Crypzip.yb”?

Malware Removal

The Trojan.Win32.Crypzip.yb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Crypzip.yb virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
FibTDryZdICG.FibTDryZdICG

How to determine Trojan.Win32.Crypzip.yb?


File Info:

crc32: FBA99FFD
md5: b921d48d992e073c5b641071b28984f6
name: B921D48D992E073C5B641071B28984F6.mlw
sha1: c02f4616d42612057ad062768a6fdf54bd6c5564
sha256: 64797d37b57cc5a503f914a94995b7c830e4b2b52e535b8b53363355b739b38f
sha512: d8de3f5e6c9d66d13ddecbdb49f035671ba17430b9f60bdd13e4a989b552e9fb703d6237146760687ad11d6d3a6e0d6e6a0cdcb1f795788e0f2b78a4e62859d4
ssdeep: 24576:l721ZpZVS0yiUZt7b9QxPsYxxELf8XltKgWeH3Y6ZdidbQ9P8xxr:t21Zo0ytNGsYXELkXlPN9Zdihfr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: long
ProductVersion: 1.0.0.0
FileVersion: 1.0.0.0
FileDescription:
Translation: 0x0000 0x04b0

Trojan.Win32.Crypzip.yb also known as:

K7AntiVirusTrojan ( 0054c4a01 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop17.61507
ClamAVWin.Packed.Filerepmalware-9864117-0
CAT-QuickHealTrojanpws.Coins
ALYacBackdoor.Agent.ServHelper
MalwarebytesMalware.AI.4230390294
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Crypzip.72c18d59
K7GWTrojan ( 0054c4a01 )
Cybereasonmalicious.6d4261
CyrenW32/Emotet.BCR.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Crypzip.yb
BitDefenderMemScan:Trojan.GenericKDZ.76333
MicroWorld-eScanMemScan:Trojan.GenericKDZ.76333
TencentWin32.Trojan.Zenpak.Pepd
Ad-AwareMemScan:Trojan.GenericKDZ.76333
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.xcsli@0
BitDefenderThetaGen:NN.ZexaF.34796.wuW@am!rPBNG
TrendMicroTROJ_GEN.R011C0WGC21
McAfee-GW-EditionBehavesLike.Win32.FakeRena.tc
FireEyeMemScan:Trojan.GenericKDZ.76333
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1140896
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba!ml
GDataWin32.Trojan.BSE.15ZSUEQ
AhnLab-V3Trojan/Win.Agent.C4544191
McAfeeArtemis!B921D48D992E
MAXmalware (ai score=100)
VBA32BScope.Trojan.Wacatac
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R011C0WGC21
RisingTrojan.Kryptik!1.D7E8 (CLASSIC)
IkarusTrojan.Win32.Krypt
FortinetW32/Coins!tr.pws
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Zenpak.HyoDgRMA

How to remove Trojan.Win32.Crypzip.yb?

Trojan.Win32.Crypzip.yb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment