Trojan

Trojan:Win32/InjectorCrypt!pz removal tips

Malware Removal

The Trojan:Win32/InjectorCrypt!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/InjectorCrypt!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/InjectorCrypt!pz?


File Info:

name: 8C97D97671CAB9C1F612.mlw
path: /opt/CAPEv2/storage/binaries/9364130f3a7994b60affbcd2d430ff6477e56fc31d388d7375d0b4ae030bfca1
crc32: 578727E6
md5: 8c97d97671cab9c1f61211e67ed3dbe3
sha1: ce30be4527224ba7a31f23e88bc8b645fb0983c1
sha256: 9364130f3a7994b60affbcd2d430ff6477e56fc31d388d7375d0b4ae030bfca1
sha512: 9c57a60d322b95a1edb5f5ecc5a386edd980feb0da5fd69f7e1ebb90103e410c896a3cb422eb610a34d1a85798a7dc377848986cef54d6737d3d1232d396ed6e
ssdeep: 3072:wfwDfFZz8q1AJr3zH8KgdI8sjt9seXZeY1YXKgeGiQ:9DfDzY1D8Kgq8srXgYmV7iQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BCD3025F2396561FE3A371FFB2AC164AD80B27388B8453E1882F6E6D758D47089C60DD
sha3_384: 19fa567de1937db497fdfa5147c3d9168f6064ddf98929b4bae6164de823cd8408032fe9b807a79e1ac0cacf6968a2ec
ep_bytes: 5589e5b90000000089f789c3bb03f223
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/InjectorCrypt!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.Heur.imW@!hBy@@e
FireEyeGeneric.mg.8c97d97671cab9c1
SkyhighBehavesLike.Win32.Generic.cm
ALYacGen:Trojan.Heur.imW@!hBy@@e
MalwarebytesTrojan.Injector.UPX
VIPREGen:Trojan.Heur.imW@!hBy@@e
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0057cf3b1 )
AlibabaTrojan:Win32/Copak.a398441f
K7GWTrojan ( 0057cf3b1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Heur.EFD32A
BitDefenderThetaAI:Packer.335106D81B
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Trojan.Heur.imW@!hBy@@e
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Copak.pe
EmsisoftGen:Trojan.Heur.imW@!hBy@@e (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Packed2.43250
ZillyaTrojan.CopakGen.Win32.1
SophosMal/HckPk-A
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Injector
KingsoftWin32.Troj.Agent.cks
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftTrojan:Win32/InjectorCrypt!pz
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Trojan.Heur.imW@!hBy@@e
VaristW32/Kryptik.DZR.gen!Eldorado
AhnLab-V3Malware/Win32.Generic.C2860595
McAfeeGenericRXAA-FA!8C97D97671CA
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D12D (CLASSIC)
YandexTrojan.Copak!ppitnytxc7Y
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.527224
DeepInstinctMALICIOUS

How to remove Trojan:Win32/InjectorCrypt!pz?

Trojan:Win32/InjectorCrypt!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment