Malware

Win32/Kryptik.BCZQ removal guide

Malware Removal

The Win32/Kryptik.BCZQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BCZQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

make.campzephyr.host
create.guitarchange.site

How to determine Win32/Kryptik.BCZQ?


File Info:

crc32: FE348F91
md5: 77346b57bffd7f5d3eee7cb08c4b95ed
name: 77346B57BFFD7F5D3EEE7CB08C4B95ED.mlw
sha1: 658bce3ad6ab1a608089490a44d5c0da7079d4ac
sha256: 1a48e4f9ed1312c1de4156532c356c68562de03ea9aeca87d8596918cc2aa559
sha512: 8a142d8ab9d1a1861cc183c68028c3726f0826586273b05eec1f780f8209626233c5b95e039b4c1ff1cf9be8bcf82541b7a616ee98cb30fc03d9775e867119cc
ssdeep: 24576:Tx00bAaHNmlKCmEgqJM02WtIlRyfRgvQm1FqIMFd+EKx5JsLN:t7xUSj0C8QC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Hzoahlataag gaowid
InternalName: IREWNEITUSDUI.EXE
FileVersion: 1.9.9.3
CompanyName: xa9Hzoahlataag gaowid
ProductName: IREWNEITUSDUI
ProductVersion: 1.9.9.3
OriginalFilename: irewneitusdui.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.BCZQ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053e4161 )
Elasticmalicious (high confidence)
ALYacGen:Heur.Mint.Zamg.1
MalwarebytesMachineLearning/Anomalous.93%
ZillyaAdware.StartSurf.Win32.64834
SangforSuspicious.Win32.Save.a
AlibabaAdWare:Win32/StartSurf.e8be37d3
K7GWTrojan ( 0053e4161 )
Cybereasonmalicious.7bffd7
CyrenW32/Kryptik.DIF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BCZQ
APEXMalicious
AvastWin32:LoadMoney-ATT [Adw]
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.StartSurf.dobs
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Heur.Mint.Zamg.1
TencentWin32.Adware.Startsurf.Agky
Ad-AwareGen:Heur.Mint.Zamg.1
SophosMal/Generic-S + IStartSurfInstaller (PUA)
ComodoMalware@#1vl1qq9yruzsc
BitDefenderThetaGen:NN.ZexaF.34236.gs0@aGJfhlai
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vt
FireEyeGeneric.mg.77346b57bffd7f5d
EmsisoftGen:Heur.Mint.Zamg.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.oic
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.28B1DD8
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Heur.Mint.Zamg.1
Acronissuspicious
McAfeePacked-FKC!77346B57BFFD
MAXmalware (ai score=84)
VBA32BScope.Adware.DownloadHelper
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
YandexPUA.StartSurf!wkkzpsF97F8
IkarusPUA.Dlhelper
FortinetW32/Kryptik.GLRL!tr
AVGWin32:LoadMoney-ATT [Adw]
Paloaltogeneric.ml

How to remove Win32/Kryptik.BCZQ?

Win32/Kryptik.BCZQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment