Malware

Win32/Kryptik.EZXT removal instruction

Malware Removal

The Win32/Kryptik.EZXT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EZXT virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

How to determine Win32/Kryptik.EZXT?


File Info:

crc32: ECB98AB1
md5: adf5c1c99990f234893cf76bfc78ba77
name: ADF5C1C99990F234893CF76BFC78BA77.mlw
sha1: f8c3540815f54855833c21df30b9a6cad3710ee0
sha256: 87f4df4212e8888f1da06c9f9d31403a734c682849a333dac00caf16bca1f061
sha512: 2eb0f52cabffb209df3d38f82d6854246c89f475aaaf441fcd10dd2510adf6bada8065967e6b78dba40ead36cca72211eef647b1477e6b8f9891de9d352bfdc6
ssdeep: 6144:88VsanFft9Y5hclqbEi1Awvnp1pnKKSguioWaiL1:8SftO5hcl3iRvp1pnKMMiR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: AQQ Sp.
FileVersion: 2.4
CompanyName: AQQ Sp. z o.o.
LegalTrademarks: AQQ Sp. z1
ProductName: AQQ IMM
ProductVersion: 1.0.0.1
OriginalFilename: AQQSp.exe
Translation: 0x0409 0x04e4

Win32/Kryptik.EZXT also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f38b21 )
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.54851
ALYacGen:Variant.Barys.54851
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Foreign.3b69a19a
K7GWTrojan ( 004f38b21 )
Cybereasonmalicious.99990f
CyrenW32/S-d2c789ae!Eldorado
ESET-NOD32a variant of Win32/Kryptik.EZXT
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.nsvz
BitDefenderGen:Variant.Barys.54851
NANO-AntivirusTrojan.Win32.Zbot.evmxfn
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
TencentMalware.Win32.Gencirc.11494ec6
SophosML/PE-A + Mal/Ransom-EE
ComodoMalware@#37s8yoify9to4
BitDefenderThetaGen:NN.ZexaF.34608.uu1@aK8HCmni
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT_FI0804A0.UVPM
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fc
FireEyeGeneric.mg.adf5c1c99990f234
EmsisoftGen:Variant.Barys.54851 (B)
AviraHEUR/AGEN.1121494
Antiy-AVLTrojan[Ransom]/Win32.Foreign
MicrosoftPWS:Win32/Zbot
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Ransom.Win32.Foreign.nsvz
GDataGen:Variant.Barys.54851
AhnLab-V3Trojan/Win32.Zbot.R214076
Acronissuspicious
McAfeeGenericRXDZ-EC!ADF5C1C99990
MAXmalware (ai score=100)
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_ZBOT_FI0804A0.UVPM
RisingRansom.Foreign!8.292 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.FCAB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Zbot.HgIASOkA

How to remove Win32/Kryptik.EZXT?

Win32/Kryptik.EZXT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment