Malware

How to remove “Win32/Kryptik.COZE”?

Malware Removal

The Win32/Kryptik.COZE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.COZE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

How to determine Win32/Kryptik.COZE?


File Info:

name: 739E9B14581C992B284C.mlw
path: /opt/CAPEv2/storage/binaries/206dc10eebd3890c10e572cf476ee493d99dbeef8899f87dc09c223fcfdc48c8
crc32: 92B142F2
md5: 739e9b14581c992b284c4b06f833d537
sha1: 0168632c020331954a89b64d01fd4b86398150fb
sha256: 206dc10eebd3890c10e572cf476ee493d99dbeef8899f87dc09c223fcfdc48c8
sha512: 24dfd939c2353d412044d68f34f6b75452440c539e7175149d0ff35107f4035687d4748fce4e3f70902a0e67f4008fc1f6027a12acbc1b4ae250b0c39d17c145
ssdeep: 6144:JYlFv8VJPNjRk1sj8x5IB9AKZBjylTuiB3R+HbdexJv2wQT9yw:0wNELgGKkqiz+HbExIjxyw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F354125E79F2C21BF039C2F1A79141C20F6E8F44683CE53B5D80CD68BA665E19B34A6D
sha3_384: 06f206de4434c178038629b29527756289788a75d377cfff293681ec947797915932efd5c16e167f1c9238f708c04d09
ep_bytes: 558bec6aff68a0a6400068b087400064
timestamp: 1984-01-10 07:36:38

Version Info:

Comments: BI0f
CompanyName: Oki Data Corporation
FileDescription: DUGIo5
FileVersion: 55, 0, 0, 3
InternalName: ooVEyW
LegalCopyright: Copyright © 2017
LegalTrademarks:
OriginalFilename: yxOZuR keCYy
PrivateBuild:
ProductName: 7 ZireUaUD
ProductVersion: 3, 0, 0, 22
SpecialBuild:

Win32/Kryptik.COZE also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.22973
MicroWorld-eScanTrojan.Ranapama.CS
FireEyeGeneric.mg.739e9b14581c992b
ALYacTrojan.Ranapama.CS
ZillyaTrojan.Zbot.Win32.170449
SangforTrojan.Win32.Ranapama.C
K7AntiVirusTrojan ( 0055dd191 )
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.4581c9
BitDefenderThetaGen:NN.ZexaF.34182.rq3@aK0@2!cI
VirITTrojan.Win32.SHeur4.CDMQ
CyrenW32/A-4a0c7173!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.COZE
TrendMicro-HouseCallTSPY_ZBOT_GE23012C.UVPA
Paloaltogeneric.ml
ClamAVWin.Trojan.Ranapama-661
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ranapama.CS
NANO-AntivirusTrojan.Win32.TrjGen.dibiks
SUPERAntiSpywareTrojan.Agent/Gen-Ranapama
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b0db9b
SophosML/PE-A + Troj/Wonton-JF
ComodoTrojWare.Win32.Kryptik.RLES@5hgp4u
BaiduWin32.Trojan.Kryptik.hx
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT_GE23012C.UVPA
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Ranapama.CS (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.egzl
AviraTR/Kryptik.rlesy
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.C8F697
KingsoftWin32.Troj.Ranapama.CS.(kcloud)
GDataTrojan.Ranapama.CS
CynetMalicious (score: 100)
AhnLab-V3HEUR/UnSec.X1469
VBA32BScope.Trojan.Waldek
TACHYONTrojan-Spy/W32.ZBot.285350
APEXMalicious
RisingMalware.Undefined!8.C (TFE:1:orL01LC8MYS)
YandexTrojan.Kryptik!oMF2fm9zFis
IkarusTrojan.Win32.Crypt
FortinetW32/Yakes.GAKM!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.COZE?

Win32/Kryptik.COZE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment