Malware

Win32/GenKryptik.CZOJ removal instruction

Malware Removal

The Win32/GenKryptik.CZOJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.CZOJ virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.ababbb.com
www.baidu.com

How to determine Win32/GenKryptik.CZOJ?


File Info:

crc32: E12E4450
md5: 57ea1fcb4079553cca9d87e6b73a33e0
name: 57EA1FCB4079553CCA9D87E6B73A33E0.mlw
sha1: 34cb3bbafa80a3021efe9cb35420e52ab408c1ca
sha256: f3a21582b70fa8e0b0b737ca76824c1a71f39c74c6ec6ce4f851e077d608d420
sha512: 2b0514bb0a0d3b7fdcae0ea02492b3ba7144dce7c19f33cf8f3f95dbcb32682c506813527f7d299c96cc9ff7ab986abf3523461520848d5761bd50007a7a1c74
ssdeep: 12288:e1Sf6SNnxOjVTOH84UqTlR5Q6CLlXpURBmu9TeeeNONkTxoRKO6XKG/hagIfA5E:emn8jA6+Q6CVpUDqeeINaxo0hagIfAa
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: UI - x57fax4e8ex672ax95fbx82b1x540dx4feex6539 x4ee3x7801 - x7d2bx82cfi x81eax5199
FileVersion: 1.0.0.1
CompanyName: x7d2bx82cfi@x7eddx5bf9x9886x57df
Comments: x7d2bx82cfi@x7eddx5bf9x9886x57df
ProductName: x672ax95fbx82b1x540d - HUM
ProductVersion: 1.0.0.1
FileDescription: x7d2bx82cfi@x7eddx5bf9x9886x57df
Translation: 0x0804 0x04b0

Win32/GenKryptik.CZOJ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.59517
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46421056
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/GenKryptik.30debf74
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.afa80a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.CZOJ
APEXMalicious
AvastWin32:Trojan-gen
BitDefenderTrojan.GenericKD.46421056
MicroWorld-eScanTrojan.GenericKD.46421056
Ad-AwareTrojan.GenericKD.46421056
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34722.UmKfauDoFbpH
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.bc
FireEyeGeneric.mg.57ea1fcb4079553c
EmsisoftTrojan.GenericKD.46421056 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.tffwg
eGambitHackTool.Generic
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2C45440
AegisLabTrojan.Win32.Malicious.4!c
GDataTrojan.GenericKD.46421056
AhnLab-V3Malware/Gen.Generic.C2141017
Acronissuspicious
McAfeeArtemis!57EA1FCB4079
MAXmalware (ai score=84)
VBA32BScope.TrojanDDoS.Macri
PandaTrj/GdSda.A
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Win32/GenKryptik.CZOJ?

Win32/GenKryptik.CZOJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment