Malware

Win32/Kryptik.LGJ malicious file

Malware Removal

The Win32/Kryptik.LGJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.LGJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Win32/Kryptik.LGJ?


File Info:

name: 618B7C229403E4662013.mlw
path: /opt/CAPEv2/storage/binaries/23611171cf30076de37c542f0f5b640ba66636fdd7f7ced683c12e3da58d4ff7
crc32: EE7A52D4
md5: 618b7c229403e466201371a68bf8a17b
sha1: 5327b048b91f5592183306e1cd4ba492946a4475
sha256: 23611171cf30076de37c542f0f5b640ba66636fdd7f7ced683c12e3da58d4ff7
sha512: 77daaa4d8bdde8c65adec09d4f00656508713ba436afe23dc48a3b3103335ebe2588e5463115078db79d001852064e7e7b926a3cee97b589d7afcc18607eda6a
ssdeep: 98304:tM6Yy6z4zCsUOwFXGi+8/t+mCrucKB38/HiEab0YRpX:tM6Yy6z2UOG/4mCqZ38/2b1RF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7463329EB42C176C089C93282DF59B8F9735685520E273E4615CE3D6E63B6E7B0EF04
sha3_384: 9de90f28003cfbbe8de40fb8100edf45ed76d4c670c18c64775694f1b9254351dd4f9891bdbddc548460d62282c12204
ep_bytes: 8d00558bec83c4bc4303cf4a41b852cc
timestamp: 2008-06-27 00:51:28

Version Info:

CompanyName: Uklvhfei Slwscrdm
FileDescription: Uklvhfei Pesjqncxi Annfoyd
FileVersion: 39,63,20,36
InternalName: Uklvhfei
LegalCopyright: Copyright © Uklvhfei Slwscrdm 1995-2010
OriginalFilename: Uklvhfei.exe
ProductName: Uklvhfei Pesjqncxi Annfoyd
ProductVersion: 56,36,128,21
Translation: 0x0409 0x04e4

Win32/Kryptik.LGJ also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader5.6625
MicroWorld-eScanGen:Heur.VIZ.!e!.1
FireEyeGeneric.mg.618b7c229403e466
ALYacGen:Heur.VIZ.!e!.1
VIPRETrojan.Win32.Kryptik.lbu (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojan:Win32/Diple.fd074614
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.29403e
BitDefenderThetaGen:NN.ZexaF.34212.@p3@a8FOPDmc
VirITTrojan.Win32.Generic.ADEN
CyrenW32/Sefnit.G.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.LGJ
TrendMicro-HouseCallBKDR_QAKBOT.SMG
Paloaltogeneric.ml
ClamAVWin.Trojan.Diple-2811
KasperskyTrojan.Win32.Diple.hlw
BitDefenderGen:Heur.VIZ.!e!.1
NANO-AntivirusTrojan.Win32.Diple.uthea
AvastWin32:Downloader-FYS [Trj]
TencentMalware.Win32.Gencirc.10b878d0
Ad-AwareGen:Heur.VIZ.!e!.1
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Diple.Win32.894
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionGenericR-IHO!618B7C229403
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Heur.VIZ.!e!.1 (B)
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Heur.VIZ.!e!.1
JiangminTrojan/Diple.afd
WebrootVir.Tool.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.19920D
ViRobotTrojan.Win32.A.Diple.5366920
ZoneAlarmTrojan.Win32.Diple.hlw
MicrosoftTrojan:Win32/Sefnit.G
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FraudPack.R3415
Acronissuspicious
McAfeeGenericR-IHO!618B7C229403
VBA32Trojan.Zeus.EA.0999
CylanceUnsafe
APEXMalicious
RisingTrojan.Win32.fedoN.ht (CLOUD)
YandexTrojan.Diple!D11kfFNU1JE
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.1768452.susgen
FortinetW32/Diple.HLW!tr
AVGWin32:Downloader-FYS [Trj]
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Kryptik.LGJ?

Win32/Kryptik.LGJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment