Malware

How to remove “Win32/Cryptoz”?

Malware Removal

The Win32/Cryptoz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Cryptoz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Cryptoz?


File Info:

name: 5BD02413DBEE65CD6BD1.mlw
path: /opt/CAPEv2/storage/binaries/1ffecdb3bc08078e322d249a672675b0c66687dda3a9c9267157c3a172a3d325
crc32: 144CC2FA
md5: 5bd02413dbee65cd6bd1a63ac52c28db
sha1: 4d82c7e922af45e044dec2c21bb69f7fc0e1bcb5
sha256: 1ffecdb3bc08078e322d249a672675b0c66687dda3a9c9267157c3a172a3d325
sha512: d7c47027a4eb90ec281eebcd58d3b1e28d7fd550f782d9cf82ff9825e135df40eb9ee2e71b2849470fd6d71bbef74136438bc9b5bb6a972fa7f33ee7e79dca0b
ssdeep: 12288:lEU6gQbwLRszz2IH3dv2jyERaOt9Zw++ky566+UJ18:lEU6gtR+ztH3de55by++kQ+yC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BD412A296ABFBD8F13ADC76FD1150381EA7EEE044814517D197E6E708B3580A12339F
sha3_384: ba81ebd13ff05ca6cfcb376c6a4f4e94271b3fde5413aea0f57d7ee20acf9584bf49ae1e35978e693e39385a297aa3ae
ep_bytes: 6864154000e8eeffffff000000000000
timestamp: 2009-03-11 09:51:40

Version Info:

Translation: 0x0409 0x04b0
ProductName: top
FileVersion: 1.08.0003
ProductVersion: 1.08.0003
InternalName: stub
OriginalFilename: stub.exe

Win32/Cryptoz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VB.kYPn
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.Dropper.Mm3@ae3bYcnk
FireEyeGeneric.mg.5bd02413dbee65cd
CAT-QuickHealVirTool.Vbinder.Gen
SkyhighBehavesLike.Win32.PWSZbot.jc
ALYacGen:Trojan.Heur.Dropper.Mm3@ae3bYcnk
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Trojan.Heur.Dropper.Mm3@ae3bYcnk
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0055e3991 )
BitDefenderGen:Trojan.Heur.Dropper.Mm3@ae3bYcnk
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.922af4
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Cryptoz
APEXMalicious
ClamAVWin.Malware.Vbinder-6841325-0
KasperskyTrojan-Downloader.Win32.Agent.bkyy
AlibabaVirTool:Win32/Vbcrypt.1030eca0
NANO-AntivirusTrojan.Win32.Agent.cnwqke
ViRobotTrojan.Win32.Downloader.75807
RisingTrojan.DL.Win32.Undef.dyq (CLASSIC)
SophosMal/VB-Z
F-SecurePacked:W32/Vbcrypt.N
DrWebTrojan.VbCrypt.250
ZillyaDownloader.Agent.Win32.14323
TrendMicroTROJ_AGENT.AOEL
EmsisoftGen:Trojan.Heur.Dropper.Mm3@ae3bYcnk (B)
IkarusBackdoor.Win32.Ruskill
JiangminTrojanDownloader.Agent.ehqq
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/VBcrypt.A.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Agent
Kingsoftmalware.kb.a.1000
MicrosoftVirTool:Win32/Vbcrypt.F
XcitiumTrojWare.Win32.VB.KLM@4xatot
ArcabitTrojan.Heur.Dropper.E62D07
ZoneAlarmTrojan-Downloader.Win32.Agent.bkyy
GDataGen:Trojan.Heur.Dropper.Mm3@ae3bYcnk
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.VBNA.R1868
McAfeeGeneric VB.kz
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.VB.gen.1
Cylanceunsafe
PandaAdware/AccesMembre.gen
TrendMicro-HouseCallTROJ_AGENT.AOEL
TencentMalware.Win32.Gencirc.10b1e4f2
YandexTrojan.GenAsa!uARcNExOdbY
SentinelOneStatic AI – Malicious PE
FortinetW32/VBInjector.fam!tr
BitDefenderThetaAI:Packer.4ABC56D424
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Cryptoz?

Win32/Cryptoz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment