Malware

Win32/Kryptik.BCLI information

Malware Removal

The Win32/Kryptik.BCLI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BCLI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Win32/Kryptik.BCLI?


File Info:

name: 0213A5368E09F7B62009.mlw
path: /opt/CAPEv2/storage/binaries/c4280771578a9af5020fa5f10c99d69c50e1502881d1765ba450fd147680e216
crc32: 549FC9FB
md5: 0213a5368e09f7b62009a9104594b1f1
sha1: dfd4062f540a5f7c2d928a7886081dd70982b237
sha256: c4280771578a9af5020fa5f10c99d69c50e1502881d1765ba450fd147680e216
sha512: c1469182a841647d8cdf47d23011e6a0afad8f0e491c38945525ddcb9c8fe5e8a31f4f406f4c6d8bdc930032a0e6af63ae526813bc6e209921c7553ec67f4fcd
ssdeep: 3072:kZptPnffub0qeGLcVrm6ixZcaDAsvgC2ZxCD2vCzC/ilcE5yCTl:kZvn50cVkHfJicC/Gc6rJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0E3C012F7D6DC52F0265A318843D6F98AA6FE21D862835B32C53F1FAD773904E61712
sha3_384: a77aa6cf69f3217334a59ba6d61562b4817f7582d852ef36ded95bd75ce09cf3314f06368cff98e99d77dc0ebdcf08e8
ep_bytes: 5589e55381eca4000000c78578ffffff
timestamp: 2013-05-31 16:28:27

Version Info:

0: [No Data]

Win32/Kryptik.BCLI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.0213a5368e09f7b6
CAT-QuickHealTrojanDropper.Gepys.A
McAfeeGeneric.atg-FAIF!0213A5368E09
Cylanceunsafe
ZillyaTrojan.ShipUp.Win32.1618
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005035811 )
AlibabaTrojanDropper:Win32/Gepys.08fcf1ea
K7GWTrojan ( 005035811 )
Cybereasonmalicious.68e09f
BaiduWin32.Trojan.Kryptik.ahj
VirITTrojan.Win32.Crypt.CIHS
CyrenW32/ShipUp.C.gen!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BCLI
APEXMalicious
ClamAVWin.Packed.Shipup-6804425-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.FKP.17
NANO-AntivirusTrojan.Win32.Mods.cqimsc
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Heur.FKP.17
AvastWin32:Kryptik-LXC [Trj]
TencentTrojan.Win32.Kryptik.bcig
EmsisoftGen:Heur.FKP.17 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen7
DrWebTrojan.Mods.1
VIPREGen:Heur.FKP.17
TrendMicroTROJ_DOFOIL.SMAD
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.high.ml.score
SophosTroj/Gepys-Fam
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.FKP.17
JiangminTrojan/ShipUp.rp
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.TrojanDropper.Gepys.BCLI@79aj7f
ArcabitTrojan.FKP.17
ViRobotTrojan.Win.Z.Mods.143864.A
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDropper:Win32/Gepys.A
GoogleDetected
AhnLab-V3Downloader/Win32.Dofoil.R68917
BitDefenderThetaAI:Packer.383AC6D41F
ALYacGen:Heur.FKP.17
MAXmalware (ai score=81)
VBA32BScope.Trojan.Mods
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DOFOIL.SMAD
RisingTrojan.Kryptik!1.A7F4 (CLASSIC)
YandexTrojan.ShipUp!Py738b7Y8QM
IkarusTrojan-Dropper.Win32.Gepys
FortinetW32/Kryptik.BCLI!tr
AVGWin32:Kryptik-LXC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.BCLI?

Win32/Kryptik.BCLI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment