Malware

Win32/Kryptik.EOKW (file analysis)

Malware Removal

The Win32/Kryptik.EOKW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.EOKW virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

wpewjgocy.uk
kfbgrcrlebcs.ru
fawxdwaibul.ru
spwocfkxcbwkvg.uk
gftbyj.ru
xumcu.us

How to determine Win32/Kryptik.EOKW?


File Info:

crc32: 6E67A517
md5: 1a6210b2edcba6875dc2ae91aeeade78
name: 1A6210B2EDCBA6875DC2AE91AEEADE78.mlw
sha1: ab0a8659882d2d36a114bc7ad3b749e3c44d279d
sha256: 976059c030c256db4a22d0fcbf2372cc3320877025154b5efeb3f7a1a26b1774
sha512: 380bf180e947c0e1bd109a480cba6c114b3fc3c5f6534f957a166379e77a0ce3fa241ae807483bec9b41fbe8d25c35320264f298461efd0b0654f272ae1fa1bd
ssdeep: 3072:vWBKecS5ns/xGmFVk0gQBlH7o+uK0IRU5cR8oa3zeBzd3An1YgCQSPH96PHNrD5:vWwej5s/x1k8B1o5QRU5V3zeBzJAn3C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Info-ZIP 1997 - 2008
InternalName: !2z
FileVersion: 5.2
CompanyName: Info-ZIP
ProductName: Zip
ProductVersion: 5.5
FileDescription: Info-2Ij 2ij for 1inme 2qnjole
OriginalFilename: m1c2.dll
Translation: 0x0409 0x04e4

Win32/Kryptik.EOKW also known as:

BkavW32.RenegilS.Trojan
K7AntiVirusTrojan ( 0055374d1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader19.28288
ClamAVWin.Ransomware.Locky-7
CAT-QuickHealRansom.Locky.S5
McAfeeRansomware-Locky
CylanceUnsafe
ZillyaTrojan.PCryptGen.Win32.1
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Locky.266f587d
K7GWTrojan ( 0055374d1 )
Cybereasonmalicious.2edcba
CyrenW32/Locky.C.gen!Eldorado
SymantecRansom.TeslaCrypt
ESET-NOD32a variant of Win32/Kryptik.EOKW
APEXMalicious
AvastWin32:Locky-E [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Locky.1
NANO-AntivirusTrojan.Win32.Dwn.eajeyj
ViRobotTrojan.Win32.Locky.Gen.A
SUPERAntiSpywareTrojan.Agent/Gen-Locky
MicroWorld-eScanGen:Heur.Locky.1
TencentTrojan.Win32.Kryptik.eokw
Ad-AwareGen:Heur.Locky.1
SophosMal/Generic-R + Troj/Agent-AQIR
ComodoTrojWare.Win32.Yakes.EQX@6b1qke
BitDefenderThetaGen:NN.ZexaF.34686.ku0@aWINMGci
VIPRETrojan.Win32.Locky.me (v)
TrendMicroRansom_LOCKY.SM0
McAfee-GW-EditionBehavesLike.Win32.Locky.ch
FireEyeGeneric.mg.1a6210b2edcba687
EmsisoftTrojan-Ransom.Win32.Locky (A)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Gen
AviraHEUR/AGEN.1102639
eGambitUnsafe.AI_Score_98%
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Locky.A
AegisLabTrojan.Win32.Locky.j!c
GDataWin32.Trojan-Ransom.Locky.K
AhnLab-V3Trojan/Win32.Locky.R174806
Acronissuspicious
VBA32SScope.Malware-Cryptor.01499
MAXmalware (ai score=100)
MalwarebytesRansom.Locky
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_LOCKY.SM0
RisingRansom.Locky!1.B656 (CLOUD)
IkarusTrojan-Ransom.Locky
FortinetW32/Locky.C!tr
AVGWin32:Locky-E [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.EOKW?

Win32/Kryptik.EOKW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment