Malware

What is “Win32/GenKryptik.EJOK”?

Malware Removal

The Win32/GenKryptik.EJOK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/GenKryptik.EJOK virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/GenKryptik.EJOK?


File Info:

crc32: 9C6891D7
md5: 068ff4cbc5a6bc62c4168af54e263520
name: biiin.exe
sha1: 7bac6e62873209f324cb710b4724062e2e59eee2
sha256: 042339f1432fa73e22e290a148dfc4a18f80a03a72bfa1e9484a86bda87f1eaf
sha512: 8f05b8f667506054805cdbff1c1fe42b4a03e766209219da31c933cb458e52cc270d2f74fc9c04093ecb8d71642e602ea0a17a743f1f852e87002db64a9022ae
ssdeep: 12288:4NItfSBA/UxaPHEBqExVTfB7Sjyj4wFFUIq1dbGNl8r4Ewc:lzka7cZfB7SmswFmIq1dyNl8kEwc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 1984-2010 Adobe Systems Incorporated and its licensors. All rights reserved.
FileVersion: 10.0.0.396
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Acrobat
ProductVersion: 10.0.0.396
FileDescription: Adobe Acrobat
OriginalFilename: Acrobat.exe
Translation: 0x0409 0x04e4

Win32/GenKryptik.EJOK also known as:

McAfeeArtemis!068FF4CBC5A6
CrowdStrikewin/malicious_confidence_60% (W)
ESET-NOD32a variant of Win32/GenKryptik.EJOK
TencentWin32.Trojan.Inject.Auto
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.high.ml.score
SentinelOneDFI – Suspicious PE
WebrootTrojan.Histboader.A
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Wacatac.C!ml
Acronissuspicious
VBA32BScope.Trojan.Agent
eGambitPE.Heur.InvalidSig

How to remove Win32/GenKryptik.EJOK?

Win32/GenKryptik.EJOK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment