Malware

Win32/Kryptik.BBEX (file analysis)

Malware Removal

The Win32/Kryptik.BBEX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BBEX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects information to fingerprint the system

How to determine Win32/Kryptik.BBEX?


File Info:

name: C748F28337892CB3EF1F.mlw
path: /opt/CAPEv2/storage/binaries/0195170788a58b4a2524b4a2a1a2cf2bfd5ac1ea47f9121ba604d1ff01ffb165
crc32: EA70E453
md5: c748f28337892cb3ef1fd8fbb4b96518
sha1: c1d7cc9741b170034281de85dd3d73e2a48e0f2d
sha256: 0195170788a58b4a2524b4a2a1a2cf2bfd5ac1ea47f9121ba604d1ff01ffb165
sha512: 0157fe079528232186b9ab13403eb31cd60ba80385b2783eaba4d788bb68e25087701d4d2659d16640cde1617b3a570ce9db15928c5058e7e3e85e183ace3675
ssdeep: 3072:IDoCDQxdIO+bD/qi8WotuSUdSyiNdi1icDPpG9mD+5aNCLgNHya:pGaIDbKWosdSJihhUm2aYkH/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0E3DF7E44C4653DF0908DF78CA48A274CAF34436B42BE096EBBC758165B4E42B2E5D7
sha3_384: e2d2a9764cecf9cd6b50fabecbcb071a9b6fc731717bcd238659fb066718c4031a3550afcffd24607fd90cb94e4b720b
ep_bytes: 5589e581ecd0000000565731ff897de8
timestamp: 2013-04-20 07:29:31

Version Info:

0: [No Data]

Win32/Kryptik.BBEX also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.96743
FireEyeGeneric.mg.c748f28337892cb3
McAfeeDropper-FEQ!C748F2833789
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Agentb.Win32.1103
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D179E7
BitDefenderThetaGen:NN.ZexaF.36196.jqX@aCJQeOo
VirITTrojan.Win32.Agent4.ANNB
CyrenW32/Flo.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BBEX
APEXMalicious
ClamAVWin.Packed.Gepys-6943335-0
KasperskyTrojan.Win32.Agentb.khd
BitDefenderTrojan.GenericKDZ.96743
NANO-AntivirusTrojan.Win32.Agent.bxpifm
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Dropper-gen [Drp]
TencentTrojan.Win32.Agentb.hae
TACHYONTrojan/W32.Agent.147512.E
EmsisoftTrojan.GenericKDZ.96743 (B)
BaiduWin32.Trojan.Kryptik.eg
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.Redirect.140
VIPRETrojan.GenericKDZ.96743
TrendMicroTROJ_KRYPTO.SMAX
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
Trapminemalicious.high.ml.score
SophosTroj/Gyepis-B
IkarusTrojan.Crypt
JiangminTrojan/Agentb.wc
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.Agentb
XcitiumTrojWare.Win32.Kryptik.ADFA@4xf7un
MicrosoftTrojan:Win32/Gepys.A!MTB
ZoneAlarmTrojan.Win32.Agentb.khd
GDataWin32.Trojan.PSE1.1SPLRJN
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R65034
VBA32SScope.Malware-Cryptor.Carberp.2313
ALYacTrojan.GenericKDZ.96743
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTO.SMAX
RisingDropper.Gepys!8.15D (TFE:1:o2ee6pq0MBK)
YandexTrojan.Agentb!ZzMWMDJXDrw
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.AZHQ!tr
AVGWin32:Dropper-gen [Drp]
Cybereasonmalicious.337892
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.BBEX?

Win32/Kryptik.BBEX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment