Categories: Malware

Should I remove “Win32/Kryptik.GYEQ”?

The Win32/Kryptik.GYEQ file is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Win32/Kryptik.GYEQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GYEQ?


General:

Operating System: Windows 7 / 8 / 8.1 / 10 Virus Name: DFI - Suspicious PE

File Info:

Name: S2Bqj5VvKiX7IOfm.exe

Size: 201386

Type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

MD5: 69266463113d65bf9f3d60be726f312d

SHA1: c00d413808ed5fda8eef1487f29d1bb84269e4fd

SH256: 7c4253b33a37e66a80a613da787b30c62173944f0ecdad098465bcc87808020e

Version Info:

[No Data]

Win32/Kryptik.GYEQ also known as:

ALYac Trojan.Agent.Emotet
APEX Malicious
AVG FileRepMalware
Ad-Aware Trojan.GenericKD.32698927
AegisLab Trojan.Win32.Generic.4!c
AhnLab-V3 Trojan/Win32.Emotet.R298664
Alibaba TrojanBanker:Win32/Emotet.806bfe1a
Antiy-AVL Trojan[Banker]/Win32.Emotet
Arcabit Trojan.Generic.D1F2F22F
Avira TR/AD.Emotet.cxhsx
BitDefender Trojan.GenericKD.32698927
BitDefenderTheta Gen:NN.ZexaF.32248.mOX@ay8v7wp
CrowdStrike win/malicious_confidence_90% (W)
Cybereason malicious.808ed5
Cylance Unsafe
Cyren W32/Emotet.AAU.gen!Eldorado
DrWeb Trojan.DownLoader30.37416
ESET-NOD32 a variant of Win32/Kryptik.GYEQ
Endgame malicious (high confidence)
F-Prot W32/Emotet.AAU.gen!Eldorado
F-Secure Trojan.TR/AD.Emotet.cxhsx
FireEye Generic.mg.69266463113d65bf
Fortinet W32/GenKryptik.DXHR!tr
GData Trojan.GenericKD.32698927
Ikarus Trojan-Banker.Emotet
Invincea heuristic
Jiangmin Trojan.Banker.Emotet.mee
K7AntiVirus Trojan ( 0055b2751 )
K7GW Trojan ( 0055b2751 )
Kaspersky HEUR:Trojan-Banker.Win32.Emotet.gen
MAX malware (ai score=81)
McAfee Emotet-FOL!69266463113D
McAfee-GW-Edition BehavesLike.Win32.Ransomware.cc
MicroWorld-eScan Trojan.GenericKD.32698927
Microsoft Trojan:Win32/Skeeyah.A!MTB
NANO-Antivirus Trojan.Win32.GenKryptik.ggmrlt
Paloalto generic.ml
Panda Trj/GdSda.A
Qihoo-360 Trojan.Generic
Rising Trojan.Generic@ML.86 (RDML:IrEb/5egRyIhM3lHSUEqUQ)
SentinelOne DFI – Suspicious PE
Sophos Mal/Generic-S
Symantec Trojan.Gen.MBT
TrendMicro TROJ_GEN.R057C0DKA19
TrendMicro-HouseCall TROJ_GEN.R057C0DKA19
VBA32 Trojan.Emotet
VIPRE Trojan.Win32.Generic!BT
Webroot W32.Trojan.Gen
ZoneAlarm HEUR:Trojan-Banker.Win32.Emotet.gen

How to remove Win32/Kryptik.GYEQ?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “MSIL/TrojanDropper.Agent.BVT”?

The MSIL/TrojanDropper.Agent.BVT is considered dangerous by lots of security experts. When this infection is active,…

12 hours ago

Should I remove “Generic.Dacic.94CCEEA9.A.A4A6DA47”?

The Generic.Dacic.94CCEEA9.A.A4A6DA47 is considered dangerous by lots of security experts. When this infection is active,…

12 hours ago

Malware.AI.524217860 removal tips

The Malware.AI.524217860 is considered dangerous by lots of security experts. When this infection is active,…

13 hours ago

Trojan:Win32/Koutodoor.F removal tips

The Trojan:Win32/Koutodoor.F is considered dangerous by lots of security experts. When this infection is active,…

13 hours ago

How to remove “Malware.AI.1412460714”?

The Malware.AI.1412460714 is considered dangerous by lots of security experts. When this infection is active,…

13 hours ago

Generic.Dacic.8952383F.A.5EC8C34B removal instruction

The Generic.Dacic.8952383F.A.5EC8C34B is considered dangerous by lots of security experts. When this infection is active,…

14 hours ago