Malware

About “Win32:MalOb-AT [Cryp]” infection

Malware Removal

The Win32:MalOb-AT [Cryp] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:MalOb-AT [Cryp] virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Icelandic
  • Anomalous binary characteristics

How to determine Win32:MalOb-AT [Cryp]?


File Info:

crc32: DCBC0751
md5: b699edb7a4c55f114f1a5dd547de33f0
name: B699EDB7A4C55F114F1A5DD547DE33F0.mlw
sha1: 451888baf2f82a5a047753940a0ee16799db74f6
sha256: 9a13f74892f7741ce9513970e7eedf2c6a7542cb362deb7c9bde4d2d6dc843a0
sha512: 6146a290a67bdda32776889955ace4f53aa4cd61b78e55d35cec7661ac24c4efd1c3d306732c2f4f5c9e26267147206fdfbd348a0cb669b3093649587697a0c5
ssdeep: 6144:e4rr6WMbp4Bov7EAS1JBEIz2/iu9GpBIXUEMpEEOhG1TMC:1eWMPK14tkbIXUEMaMTMC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32:MalOb-AT [Cryp] also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 0055e3db1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.31
CynetMalicious (score: 100)
McAfeePWS-Zbot.gen.afh
CylanceUnsafe
ZillyaTrojan.XBlocker.Win32.910
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Obfuscator.cb2a1f7f
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.7a4c55
CyrenW32/Trojan.IYLJ-1333
SymantecW32.Pilleuz!gen6
ESET-NOD32Win32/Spy.Zbot.JF
APEXMalicious
AvastWin32:MalOb-AT [Cryp]
ClamAVWin.Trojan.Xblocker-50
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Kelios.1
NANO-AntivirusTrojan.Win32.Zbot.bdfmc
MicroWorld-eScanGen:Heur.Kelios.1
TencentWin32.Trojan.Xblocker.Pgcv
Ad-AwareGen:Heur.Kelios.1
SophosML/PE-A + Mal/FakeAV-BT
ComodoMalCrypt.Indus!@1qrzi1
BitDefenderThetaGen:NN.ZexaF.34628.uqZ@aGlc9oaK
VIPREVirTool.Win32.Obfuscator.hg!a (v)
TrendMicroTROJ_KRAP.SMFB
McAfee-GW-EditionBehavesLike.Win32.ZBot.fc
FireEyeGeneric.mg.b699edb7a4c55f11
EmsisoftGen:Heur.Kelios.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.zgr
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.XPACK.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Blocker
ArcabitTrojan.Kelios.1
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.Kelios.1
TACHYONTrojan/W32.Agent.339968.GG
AhnLab-V3Trojan/Win32.FakeAV.R96
Acronissuspicious
VBA32Trojan.ExpProc.014
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.95%
PandaGeneric Malware
TrendMicro-HouseCallTROJ_KRAP.SMFB
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.Meredrop!9rbZqXGkjRk
IkarusTrojan-Ransom.XBlocker
MaxSecureTrojan.Malware.2017949.susgen
FortinetW32/Zbot.NT!tr
AVGWin32:MalOb-AT [Cryp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HxQBHL8A

How to remove Win32:MalOb-AT [Cryp]?

Win32:MalOb-AT [Cryp] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment