Malware

About “Win32/Kryptik.ACZO” infection

Malware Removal

The Win32/Kryptik.ACZO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.ACZO virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Win32/Kryptik.ACZO?


File Info:

name: 99226BD55B0690A8ED16.mlw
path: /opt/CAPEv2/storage/binaries/7cdc87440d3a1cd7eee6a711bd4244b23a9de47d97d4a5d35b512bb6fb65e743
crc32: 63B9FEF0
md5: 99226bd55b0690a8ed166aac368ba839
sha1: cdbcdd5547050753b3e0f6a8c412754da4fdd6e2
sha256: 7cdc87440d3a1cd7eee6a711bd4244b23a9de47d97d4a5d35b512bb6fb65e743
sha512: 0ffbc6c88274bc3cdaf116c692a33eb2a32d27368d250b0e2b451f7b371f14e1f2acb0caf19ed95cdf9bc1cc8e60e6acdbf3c2376d83bbd8ef99532c8c581fc8
ssdeep: 6144:J1+VmPaeGyhdtnspJhKmH80tSaqvKS0EmJDsxlimxO:J4sSLEQpJhiCSASnk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC54C0E2A608C042D8356277CB11C85B832C1F369E9B3ABD516C3F58F3F52C15AD5EA9
sha3_384: 1d7626c20c979bbf5fa7c5b0714d4cdb3d13db87d316500de82bc54e9bfc7b9657b731f20b30e0e678bc8e3e2a9f0376
ep_bytes: 558bec83c4ac528b353c00430081f600
timestamp: 2011-01-12 07:37:58

Version Info:

CompanyName: Don HO don.h@free.fr
FileDescription: Notepad++ : a free (GNU) source code editor
FileVersion: 5.7
InternalName: npp.exe
LegalCopyright: Copyleft 1998-2006 by Don HO
OriginalFilename: Notepad++.exe
ProductName: Notepad++
ProductVersion: 5.7
Translation: 0x0409 0x04b0

Win32/Kryptik.ACZO also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.20373
MicroWorld-eScanGen:Heur.Mint.Zard.24
FireEyeGeneric.mg.99226bd55b0690a8
ALYacGen:Heur.Mint.Zard.24
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Kryptik.73499efc
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.55b069
BitDefenderThetaGen:NN.ZexaF.34182.rm1@a4d9K9ki
VirITTrojan.Win32.Generic.BDVD
CyrenW32/S-aa63700b!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ACZO
TrendMicro-HouseCallTROJ_FRS.0NA103BO20
ClamAVWin.Trojan.Zbot-21567
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.24
NANO-AntivirusTrojan.Win32.Zbot.rgeln
AvastWin32:Reveton-Y [Trj]
TencentMalware.Win32.Gencirc.114929ff
Ad-AwareGen:Heur.Mint.Zard.24
TACHYONTrojan-Spy/W32.ZBot.286720.U
EmsisoftGen:Heur.Mint.Zard.24 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Zbot.Win32.59581
TrendMicroTROJ_FRS.0NA103BO20
McAfee-GW-EditionPWS-Zbot.gen.azb
SophosMal/Generic-R + Mal/EncPk-ABFO
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Heur.Mint.Zard.24
JiangminTrojanSpy.Zbot.bnev
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.F6B44A
KingsoftWin32.Troj.Zbot.dg.(kcloud)
ViRobotTrojan.Win32.A.Zbot.286720.O
MicrosoftBackdoor:Win32/Ursap!rts
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R20107
Acronissuspicious
McAfeePWS-Zbot.gen.azb
MAXmalware (ai score=100)
VBA32Malware-Cryptor.General.3
MalwarebytesTrojan.Agent
APEXMalicious
RisingBackdoor.Ursap!8.8D6 (CLOUD)
YandexTrojan.GenAsa!G/3YIhLJCCs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3508004.susgen
FortinetW32/Zbot.DGEQ!tr
AVGWin32:Reveton-Y [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.ACZO?

Win32/Kryptik.ACZO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment