Malware

Joke:Win32/Kokegift.A malicious file

Malware Removal

The Joke:Win32/Kokegift.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Joke:Win32/Kokegift.A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Joke:Win32/Kokegift.A?


File Info:

name: E78E753ADF4F4344A607.mlw
path: /opt/CAPEv2/storage/binaries/6193b92afb0010619f5bc291b5779830bc6de28bb512029fdca7d50bb56e3ce1
crc32: F2F60C79
md5: e78e753adf4f4344a607e64db5190498
sha1: 92579b48ab3e8a4d7c5a0d2961be66a1347fe7bc
sha256: 6193b92afb0010619f5bc291b5779830bc6de28bb512029fdca7d50bb56e3ce1
sha512: e505d0dad4c23d7093e5a3f2a1eaeb856f1757f3ad9af0467f3be6497ba9b5b62ed81eb943acbeb62aaf637338571b0ca49437e966c51dba7db17dbba1e8c932
ssdeep: 3072:x6OO4DWsPN2bEGmS7YzUnq1bruYSf37lf:YOxWslscSmPhrLSfLN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169B3F233C7E99A6AD4EDD170469E8D1B973CE46F6342575A01F22C1D3F07A68AB31A20
sha3_384: a9a4bbf4b2a5f9052e6199b5b40909098d06596801862ee65e53af9c111c2c5b47860374754f9f93ebafb7ebb3534ab7
ep_bytes: 60e872050000eb3387db900070430008
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Joke:Win32/Kokegift.A also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Jacard.194831
McAfeeJoke-Geschenk
ZillyaTrojan.Agent.Win32.169193
SangforRiskware.Win32.Kokegift.A
BitDefenderGen:Variant.Jacard.194831
K7GWTrojan ( 7000000f1 )
K7AntiVirusTrojan ( 7000000f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Joke.CDEject.A potentially unsafe
APEXMalicious
ClamAVWin.Joke.Coke-1
NANO-AntivirusRiskware.Win32.Geschenk.bdflz
AvastFileRepMetagen [PUP]
Ad-AwareGen:Variant.Jacard.194831
EmsisoftGen:Variant.Jacard.194831 (B)
ComodoMalware@#1g5squ95apdeu
DrWebJoke.Geschenk
VIPREJoke.Win32.Kokegift.A (not malicious)
TrendMicroJOKE_GESCHENK.A
McAfee-GW-EditionJoke-Geschenk
FireEyeGen:Variant.Jacard.194831
SophosGeneric PUA JC (PUA)
IkarusTrojan-Spy.Zbot
GDataGen:Variant.Jacard.194831
WebrootJoke:Kokegift.A
AviraJOKE/Cokegift.3
Antiy-AVLTrojan/Generic.ASMalwS.10E3E8B
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Jacard.D2F90F
MicrosoftJoke:Win32/Kokegift.A
CynetMalicious (score: 99)
AhnLab-V3Win-AppCare/Geschenk.112640
ALYacGen:Variant.Jacard.194831
MAXmalware (ai score=98)
CylanceUnsafe
TrendMicro-HouseCallJOKE_GESCHENK.A
TencentWin32.Trojan.Geschenk.Akyw
YandexTrojan.Fakealert!P6o+qUFvW74
eGambitUnsafe.AI_Score_77%
BitDefenderThetaGen:NN.ZelphiF.34294.gOWbaOm1Tsbi
AVGFileRepMetagen [PUP]
Cybereasonmalicious.adf4f4
PandaJoke/Posa
MaxSecureTrojan.Malware.300983.susgen

How to remove Joke:Win32/Kokegift.A?

Joke:Win32/Kokegift.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment