Malware

Win32/Kryptik.BAGN (file analysis)

Malware Removal

The Win32/Kryptik.BAGN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BAGN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial binary language: Bulgarian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win32/Kryptik.BAGN?


File Info:

crc32: EC7E62E0
md5: 80bb407aae08698a72bc4b034ab21cb0
name: 80BB407AAE08698A72BC4B034AB21CB0.mlw
sha1: 15a80ef626694876e32fd91dc61f4d4e36be8bd1
sha256: eb6a910903b502078e0a4a756b47bbc69e4de50d84a2ae6dbcc019b0e03d6e5a
sha512: db9e3137d526de7a969f73ef5bca6ff4c3e5d3b908c059c781360bfcd2401a3b471f0d1f96325a9908c300d38e549526430b884467f1ec1afe000af4767c83f6
ssdeep: 6144:laAa/RBiL0GFXryC7rMC/LZiSXoIEXU6XoF+Cv5W:laAC+YG1yCR/gnXnXoF+X
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2005-2013 - STDIO Labs Software
InternalName: wmceta
FileVersion: 6.4.1.3
CompanyName: STDIO Labs Software
ProductName: WMC Easy Transfer Autoplay
ProductVersion: 6.4.1.3
FileDescription: WMC Easy Transfer Autoplay
OriginalFilename: wmceta.exe
Translation: 0x0402 0x04b0

Win32/Kryptik.BAGN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055dd191 )
DrWebTrojan.PWS.Panda.2401
CynetMalicious (score: 100)
CAT-QuickHealTrojanSpy.Zbot.Y
ALYacGen:Variant.Symmi.20325
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.122460
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanPSW:Win32/Bulta.d8d63164
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.aae086
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BAGN
APEXMalicious
AvastWin32:Ransom-AIJ [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.20325
NANO-AntivirusTrojan.Win32.Zbot.dsbtry
MicroWorld-eScanGen:Variant.Symmi.20325
TencentMalware.Win32.Gencirc.10ba676c
Ad-AwareGen:Variant.Symmi.20325
SophosTroj/Zbot-EYX
ComodoMalware@#2hgt4l6kqz9n8
BitDefenderThetaGen:NN.ZexaF.34628.pmLfa0iFPOaQ
VIPRETrojan.Win32.Reveton.b!ag (v)
TrendMicroTSPY_ZBOT.SML0
McAfee-GW-EditionRansom-FBLR!C761842A3BCB
FireEyeGeneric.mg.80bb407aae08698a
EmsisoftGen:Variant.Symmi.20325 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.diqh
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1129207
eGambitGeneric.PSW
KingsoftWin32.Troj.Zbot.lg.(kcloud)
MicrosoftPWS:Win32/Zbot
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Symmi.20325
TACHYONTrojan-Spy/W32.ZBot.335494
AhnLab-V3Spyware/Win32.Zbot.C167201
Acronissuspicious
McAfeeArtemis!80BB407AAE08
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SML0
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!SElBuQD6RQ8
IkarusTrojan-Ransom.Foreign
FortinetW32/Zbot.AAO!tr
AVGWin32:Ransom-AIJ [Trj]
Qihoo-360Win32/Trojan.Ransom.085

How to remove Win32/Kryptik.BAGN?

Win32/Kryptik.BAGN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment