Malware

Win32/Kryptik.GOGJ information

Malware Removal

The Win32/Kryptik.GOGJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GOGJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Win32/Kryptik.GOGJ?


File Info:

name: AC2D6E81C3D9A28060A0.mlw
path: /opt/CAPEv2/storage/binaries/0a817e7c40ddcc7baf535bb455ed4f0d3a887c5197dc5d1abb61a5e4bda943c5
crc32: 3DDEAF2A
md5: ac2d6e81c3d9a28060a076f3e00355da
sha1: f99cbaf3faad0590b2ef22711898cd349feb9be5
sha256: 0a817e7c40ddcc7baf535bb455ed4f0d3a887c5197dc5d1abb61a5e4bda943c5
sha512: b889c6a8b0b8ec80c68331e705c3681462eb3ef0c0e8b8cd109c04b90dc9cd1a67def3a057a05f2d5c339e842e35ae56255b62d6864142ba23a0388f1ae524e2
ssdeep: 6144:1g7qAFngU8kNYu57DbBKk5Kc6diWjBN1Wmh1osDoIc5PYbLmNLRVaMIkM:1g77FZYs3bBKkrnW1XFD3gYbLmnFIkM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179B4AF62BECD88F0E06715318C36CE79453FBEAD89308D5B21DD7B5B3A722C642355A2
sha3_384: 1fcde0f97fa796c5142a9a1366a8a22da86041acd024f790c3cfc10ce7c5359ff92285870d406adb6951f807e311f661
ep_bytes: e8822e0000e9000000006a1468b8bc04
timestamp: 2015-12-28 12:17:18

Version Info:

CompanyName: Netwrix Wide
FileDescription: Equatespend
FileVersion: 14.0.89.93
InternalName: Equatespend.exe
LegalCopyright: 2019 Netwrix Wide, Inc. All Rights Reserved
OriginalFilename: Equatespend.exe
ProductName: Equatespend
Translation: 0x0409 0x04e4

Win32/Kryptik.GOGJ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.53
FireEyeGeneric.mg.ac2d6e81c3d9a280
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeArtemis!AC2D6E81C3D9
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.71158
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005449bf1 )
AlibabaTrojan:Win32/Yakes.d6e01720
K7GWTrojan ( 005449bf1 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34212.Eu0@a8MW!ggi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GOGJ
AvastFileRepMalware
KasperskyTrojan.Win32.Yakes.yiqm
BitDefenderGen:Heur.Mint.Zard.53
NANO-AntivirusTrojan.Win32.Yakes.flrden
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
TencentWin32.Trojan.Yakes.Lmun
Ad-AwareGen:Heur.Mint.Zard.53
SophosMal/Generic-S
ComodoMalware@#2buoe2je062z0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Heur.Mint.Zard.53 (B)
Paloaltogeneric.ml
GDataGen:Heur.Mint.Zard.53
JiangminTrojan.Yakes.abxm
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1205424
Antiy-AVLTrojan/Generic.ASMalwS.2A16F1C
ViRobotTrojan.Win32.Z.Yakes.503296
ZoneAlarmTrojan.Win32.Yakes.yiqm
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3291145
ALYacGen:Heur.Mint.Zard.53
MAXmalware (ai score=100)
VBA32Trojan.Yakes
MalwarebytesTrojan.Yakes
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Yakes!7hlyE7Zfx+o
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GOET!tr
AVGFileRepMalware
Cybereasonmalicious.1c3d9a
PandaTrj/GdSda.A

How to remove Win32/Kryptik.GOGJ?

Win32/Kryptik.GOGJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment