Trojan

Trojan.Win32.Propagate.ntz (file analysis)

Malware Removal

The Trojan.Win32.Propagate.ntz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Propagate.ntz virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r5—sn-4g5e6nl6.gvt1.com

How to determine Trojan.Win32.Propagate.ntz?


File Info:

crc32: 3BD31DBA
md5: 000ed5c20aa8f94000d407c5f6a15d88
name: socks111atx.exe
sha1: 5c883ef4990398d86dcdd2e98382f8d1d0b87769
sha256: 363a035ec780632af17429626e37d67f319a174f615e820617c1b55734f03d85
sha512: 1b1cf772a64250cc42e0baabf134a6382d4af4efff36a6f5e5243fb3a1c10156cb7f3404ed9bcdcbd8ebfcb87127708622dcbdf81c24ac1ea278741acc1a1c2a
ssdeep: 3072:oSYoDOyGkBz6Oa35NZXk34n52Z08hwbOyBr2La3:oSdDOyGkByAfwbv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0219 0x04e4

Trojan.Win32.Propagate.ntz also known as:

MicroWorld-eScanTrojan.GenericKD.32771441
FireEyeGeneric.mg.000ed5c20aa8f940
ALYacTrojan.GenericKD.32771441
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.32771441
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.499039
BitDefenderThetaGen:NN.ZexaF.32517.ju0@aOYeE8i
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_FRS.VSNW1EK19
GDataTrojan.GenericKD.32771441
KasperskyTrojan.Win32.Propagate.ntz
AegisLabTrojan.Multi.Generic.4!c
APEXMalicious
RisingTrojan.Wacatac!8.10C01 (TFE:5:MW2xy0algLO)
Ad-AwareTrojan.GenericKD.32771441
SophosMal/Generic-S
ComodoMalware@#g6f0gowo5ir3
F-SecureTrojan.TR/AD.MalwareCrypter.bldbh
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
SentinelOneDFI – Suspicious PE
JiangminTrojanDownloader.Bandit.ayy
WebrootW32.Malware.Gen
AviraTR/AD.MalwareCrypter.bldbh
MAXmalware (ai score=80)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F40D71
ZoneAlarmTrojan.Win32.Propagate.ntz
MicrosoftTrojan:Win32/GandCrypt.GE!MTB
AhnLab-V3Malware/Win32.RL_Generic.R301699
Acronissuspicious
McAfeeArtemis!000ED5C20AA8
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.MalPack.GS
PandaGeneric Malware
ESET-NOD32a variant of Win32/Kryptik.GYYS
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GYYS!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.2bc

How to remove Trojan.Win32.Propagate.ntz?

Trojan.Win32.Propagate.ntz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment