Malware

Win32:Kryptik-OZX [Trj] removal

Malware Removal

The Win32:Kryptik-OZX [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Kryptik-OZX [Trj] virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32:Kryptik-OZX [Trj]?


File Info:

name: 0443F41CC408F0BBE4B7.mlw
path: /opt/CAPEv2/storage/binaries/83ebb1253128eaf42df85570f29274501533813fe0a4d40d1a2ab7320cc4d303
crc32: 058E76D2
md5: 0443f41cc408f0bbe4b769b9d5b4d1ac
sha1: e5a0a8f0dd235c8654f1d4014df3d3e61af42c66
sha256: 83ebb1253128eaf42df85570f29274501533813fe0a4d40d1a2ab7320cc4d303
sha512: 1ef2ed915c830b45a12c53a3d818c382de95c231d891b09685a954eb4c96726d755e08f07326ec06a750e308eeb64284fde42eb6ea84fb14ff8df72af09e5905
ssdeep: 384:f+LOPUVxjbKLTDjzB9gtA5Z7p1MJXOsdRTfKGs:kOPcjbKLvjotu1MJXOsdRLY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1380384544EC202D6D6528DBB84B6F28E469CFC23E1434D9CAA71FB4487F23D26872D5C
sha3_384: 491209d27d51822abd20a25b0b0b0840750a807d7f093fb9312bdc0e80bb58052026d94b292aa389dcef49a66fd502b9
ep_bytes: 608bdc6681fb00ff0f871c0000000f87
timestamp: 2014-04-23 07:37:18

Version Info:

0: [No Data]

Win32:Kryptik-OZX [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.mfmY
MicroWorld-eScanTrojan.GenericKDZ.95558
FireEyeTrojan.GenericKDZ.95558
CAT-QuickHealTrojanDownloader.Upatre.AA3
McAfeeDownloader-FSH!0443F41CC408
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004a97a31 )
AlibabaTrojanDownloader:Win32/Waski.dd1d0c89
K7GWTrojan ( 004a97a31 )
Cybereasonmalicious.0dd235
BaiduWin32.Trojan-Downloader.Waski.b
CyrenW32/A-87e626ef!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Upatre-6801230-0
BitDefenderTrojan.GenericKDZ.95558
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Kryptik-OZX [Trj]
TencentTrojan-DL.Win32.Waski.zb
EmsisoftTrojan.GenericKDZ.95558 (B)
F-SecureTrojan.TR/Dldr.Waski.G
DrWebTrojan.Upatre.1
VIPRETrojan.GenericKDZ.95558
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Ardurk.nz
SophosTroj/Agent-AIRG
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE1.1XG9TWZ
JiangminTrojan/Cutwail.id
GoogleDetected
AviraTR/Dldr.Waski.G
Antiy-AVLTrojan/Win32.SGeneric
XcitiumTrojWare.Win32.Downloader.Waski.FO@5h1d8h
ArcabitTrojan.Generic.D17546
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R118957
ALYacTrojan.GenericKDZ.95558
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.Kryptik!1.A90C (CLASSIC)
YandexTrojan.Kryptik!oUAqRIL0aVI
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Agent.BAVS!tr
AVGWin32:Kryptik-OZX [Trj]
DeepInstinctMALICIOUS

How to remove Win32:Kryptik-OZX [Trj]?

Win32:Kryptik-OZX [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment