Malware

Win32/Kryptik.BGOH malicious file

Malware Removal

The Win32/Kryptik.BGOH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BGOH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.BGOH?


File Info:

name: 715A0DAB95A40BA81C9B.mlw
path: /opt/CAPEv2/storage/binaries/9386b1a4e3a81189323876473e42f2b9dfa337c6c626f6088c20a22fb67be3b0
crc32: FAD359F1
md5: 715a0dab95a40ba81c9b205c355ef4a3
sha1: 8a4493ff2c80a4d598f8b6134e16b7c6a280376b
sha256: 9386b1a4e3a81189323876473e42f2b9dfa337c6c626f6088c20a22fb67be3b0
sha512: 00b7fb10d5e0f95d2d8952318b5bb4f32ba980944fd88ab5222a0f7361957a2c298410d8078f3583422856d74faff061f284873e0a2cc5eaf9f4e5da6755c455
ssdeep: 6144:15+2BxAWURf/bhwKKloaKDiI27zzl7FUSbGqJq:1E5WURf/bLK3KDX8zzl7FUS6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160547A0C163788F2CCF5BCB089A17AB026391FDD260FA61B99507F39DB3D1E2A585746
sha3_384: 4d1124b34d8964292122a296dc8387e160295a7a96a6d9c128cee683ff44ce8badf7dc3106ba9ff6a1f34cede35ed185
ep_bytes: 558bec83ec2856e844ffffff05151605
timestamp: 2013-07-25 03:59:04

Version Info:

CompanyName: Hilgraeve, Inc.
FileDescription: HyperTerminal Applet
FileVersion: 5.1.2600.0
Translation: 0x0409 0x0000

Win32/Kryptik.BGOH also known as:

BkavW32.AIDetectMalware
AVGWin32:Kryptik-MMY [Trj]
tehtrisGeneric.Malware
DrWebTrojan.Mods.1
MicroWorld-eScanTrojan.GenericKDZ.95265
FireEyeGeneric.mg.715a0dab95a40ba8
CAT-QuickHealTrojanDropper.Gepys.A
ALYacTrojan.GenericKDZ.95265
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.95265
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005110401 )
K7GWTrojan ( 005110401 )
Cybereasonmalicious.f2c80a
BitDefenderThetaGen:NN.ZexaF.36662.r01@aeQh4IGi
VirITTrojan.Win32.Generic.JKV
CyrenW32/Zaccess.BD.gen!Eldorado
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BGOH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-1214795
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.95265
NANO-AntivirusTrojan.Win32.Mods.cqjowu
SUPERAntiSpywareAdware.Graftor/Variant
AvastWin32:Kryptik-MMY [Trj]
RisingTrojan.Kryptik!1.AB59 (CLASSIC)
F-SecureTrojan.TR/Crypt.XPACK.Gen
BaiduWin32.Trojan.Kryptik.as
ZillyaTrojan.Kryptik.Win32.406270
TrendMicroTROJ_SPNR.15HD13
Trapminemalicious.high.ml.score
SophosMal/Zbot-MX
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bbvdn
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.Kryptik.BFIV@5013ii
ArcabitTrojan.Generic.D17421
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.5ITLLW
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R73526
VBA32Malware-Cryptor.Bambarbiya
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.15HD13
TencentMalware.Win32.Gencirc.10b106e5
YandexTrojan.GenAsa!2T+Jb7hLUkg
IkarusTrojan.Win32.Reveton
MaxSecureTrojan.ShipUp.gen
FortinetW32/ZBOT.QT!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.BGOH?

Win32/Kryptik.BGOH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment