Malware

About “Win32/Kryptik.BGMH” infection

Malware Removal

The Win32/Kryptik.BGMH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BGMH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.BGMH?


File Info:

name: D85865182D6975B9E85D.mlw
path: /opt/CAPEv2/storage/binaries/1313b21f97e29a59200a83dc2af072feee6b570417cac6734434d37b74a6a3cf
crc32: 2D3145A1
md5: d85865182d6975b9e85df5c8a23206c6
sha1: 69f7e5017983f30cd47399956c7775c8fcb51a52
sha256: 1313b21f97e29a59200a83dc2af072feee6b570417cac6734434d37b74a6a3cf
sha512: 23f1cb8c31c3dcbaa6dabdfb4ba6d000d578b962ff972de0d5683403fc9244f2d2e723d61580a391997bff7eaf753c500ad240ebfa1fa7310edd7b3104b90c67
ssdeep: 6144:lJ3p/dvbN3LOLz5jWzokTviaFjSt9Eh1ROSunBwSbGqJW:n3p/dx30jWskTqqjcOvh9Sm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D547B472783D88EDD29A138404EBEFE3A69DF1126073442A1E4B737D931AD3199A377
sha3_384: a47bea79e2af325b02bc8e964e19d9f9600a076e15e120dbedbf9d2747e30e111f8965b5bcfd7ae8006c7313634f4d53
ep_bytes: 558bec83ec2856e844ffffff05151605
timestamp: 2013-07-23 15:59:41

Version Info:

CompanyName: Hilgraeve, Inc.
FileDescription: HyperTerminal Applet
FileVersion: 5.1.2600.0
Translation: 0x0409 0x0000

Win32/Kryptik.BGMH also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.d85865182d6975b9
CAT-QuickHealTrojanDropper.Gepys.A
ALYacGen:Heur.Japik.6
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.384062
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005110401 )
K7GWTrojan ( 005110401 )
Cybereasonmalicious.82d697
BitDefenderThetaGen:NN.ZexaF.36250.rW1@a4mFNCGi
VirITTrojan.Win32.Generic.IET
CyrenW32/Zaccess.BD.gen!Eldorado
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BGMH
APEXMalicious
ClamAVWin.Trojan.Agent-1344701
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Japik.6
NANO-AntivirusTrojan.Win32.Mods.cqhznn
MicroWorld-eScanGen:Heur.Japik.6
AvastWin32:Kryptik-MMY [Trj]
TencentMalware.Win32.Gencirc.10b3a4f6
SophosMal/Zbot-MX
BaiduWin32.Trojan.Kryptik.as
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Mods.1
VIPREGen:Heur.Japik.6
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dh
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Japik.6 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.5ITLLW
JiangminTrojan/Generic.aywzu
WebrootW32.Trojan.Fpkc
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.Kryptik.BFIV@5013ii
ArcabitTrojan.Japik.6
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Vindor!pz
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R73526
McAfeeZeroAccess-FBI!D85865182D69
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Bambarbiya
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB59 (CLASSIC)
YandexTrojan.GenAsa!i9uEQYAEcIc
IkarusTrojan.Win32.Reveton
MaxSecureTrojan.ShipUp.gen
FortinetW32/Lockscreen.LOA!tr
AVGWin32:Kryptik-MMY [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.BGMH?

Win32/Kryptik.BGMH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment