Malware

Win32/Kryptik.GJUG malicious file

Malware Removal

The Win32/Kryptik.GJUG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GJUG virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Created a service that was not started

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Kryptik.GJUG?


File Info:

crc32: 21FFD867
md5: 57fd66671e3f9c3ed96e268bba6524be
name: 95a.exe
sha1: 85b0e5e80b4c3f3662d170fdc850b06c5273c5a7
sha256: fd1bb76f68b7b1d8e66bda211285afc41b41b5e97bdf015f761c74101055b6e3
sha512: 7fec95775b3d0acb1fb20d86bbd94522a2320c39082278f758ea999cc36d02673657bcdb0f2108a04245322739c9776b458b707bf08d03a4ea10dc7a82dd554e
ssdeep: 24576:kzWneE+PBa3PA815O6HSkX1CAG2R/7SSltMXZnJZr+IFhUBy1NBfkNS2qoMHAyU:kzWfQIPBSkX1CGSZNJV+Yq812qTANa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 fCoder SIA 2016. All rights reserved.
InternalName: 2Printer
FileVersion: 5.3.0.0
CompanyName: xa9 fCoder SIA 2016
ProductName: 2Printer
ProductVersion: 5.3.0.0
FileDescription: 2Printer
OriginalFilename: 2Printer.exe
Translation: 0x0009 0x04b0

Win32/Kryptik.GJUG also known as:

MicroWorld-eScanTrojan.GenericKD.40522799
FireEyeGeneric.mg.57fd66671e3f9c3e
McAfeeGenericR-NPQ!57FD66671E3F
MalwarebytesTrojan.SpamBot
ZillyaTrojan.Yakes.Win32.69427
BitDefenderTrojan.GenericKD.40522799
TrendMicroTROJ_GEN.R007C0DDR19
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
GDataTrojan.GenericKD.40522799
KasperskyTrojan.Win32.Yakes.xjms
AlibabaTrojan:Win32/Yakes.236fad50
NANO-AntivirusTrojan.Win32.Yakes.fijnps
AegisLabTrojan.Win32.Yakes.4!c
RisingSpammer.Morphisil!8.E55A (C64:YzY0OuxvRViKoIxa)
Ad-AwareTrojan.GenericKD.40522799
EmsisoftTrojan.GenericKD.40522799 (B)
ComodoTrojWare.Win32.TrojanProxy.Bunitu.RV@872vc7
F-SecureHeuristic.HEUR/AGEN.1036312
DrWebTrojan.Ssebot.2
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Ransomware.tc
SophosMal/Generic-S
IkarusTrojan.Win32.Emotet
CyrenW32/Trojan.EZTG-6298
Endgamemalicious (high confidence)
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1036312
Antiy-AVLTrojan/Win32.Yakes
MicrosoftTrojan:Win32/Emotet.PB
ArcabitTrojan.Generic.D26A542F
SUPERAntiSpywareTrojan.Agent/Gen-Bunitu
AhnLab-V3Malware/Win32.Generic.C2735349
ZoneAlarmTrojan.Win32.Yakes.xjms
ESET-NOD32a variant of Win32/Kryptik.GJUG
Acronissuspicious
VBA32BScope.Trojan.Yakes
ALYacTrojan.GenericKD.40522799
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R007C0DDR19
TencentWin32.Trojan.Yakes.Szcf
YandexTrojan.Yakes!2ukvcZ2Xjmw
SentinelOneDFI – Malicious PE
FortinetW32/GenKryptik.CRTH!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.71e3f9
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.c51

How to remove Win32/Kryptik.GJUG?

Win32/Kryptik.GJUG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment