Malware

Win32/Kryptik.BPMF removal tips

Malware Removal

The Win32/Kryptik.BPMF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BPMF virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.BPMF?


File Info:

name: 6E196814BFCD3F528F73.mlw
path: /opt/CAPEv2/storage/binaries/b6a6091ee72a433f71d0a280c87642333e4cadb949fa9db6a4ad463c65718161
crc32: 532F3F6E
md5: 6e196814bfcd3f528f7380ecee112bb1
sha1: acfa5a3dfbe0c087dbaf845a8f60eaa5b8ed186d
sha256: b6a6091ee72a433f71d0a280c87642333e4cadb949fa9db6a4ad463c65718161
sha512: 339f473673c63adf9d2e65e3dd174f54c18df5153a744b98b3e9c4b0e36af260a3d1445ee10cc4d87fcb2f4816aa5821733a99ab6837f560adc6f22a6982b622
ssdeep: 768:QDRRH+9lFh0ul16sh7iQroCHUf+RjFBSuB2Xt:QFl+Z16sh7iQroCbRB0uw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F203643A5ED10473D37395B098F2AEF2B42EBD193815890D60C9F74A4CB3B92AD91D1E
sha3_384: 878ada239f7fe887490208a1f818ff3f1045a25ce23010f24932c356fef062fd12f82a5d3bb16040002a348dd1bdce88
ep_bytes: e88c020000e957fdffff8bff558bec8b
timestamp: 2013-11-21 06:23:38

Version Info:

0: [No Data]

Win32/Kryptik.BPMF also known as:

BkavW32.FamVT.GeND.Trojan
LionicTrojan.Win32.LdPinch.tntX
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.6e196814bfcd3f52
CAT-QuickHealTrojan.ZbotRI.S28718216
SkyhighBehavesLike.Win32.PWSZbot.nm
McAfeeArtemis!6E196814BFCD
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.LdPinch.Win32.29463
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
BitDefenderTrojan.Ppatre.Gen.1
K7GWTrojan-Downloader ( 0055c6c71 )
Cybereasonmalicious.4bfcd3
VirITTrojan.Win32.Generic.CJD
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BPMF
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Razy-9935848-0
KasperskyTrojan-PSW.Win32.LdPinch.hij
NANO-AntivirusTrojan.Win32.LdPinch.cqjkmt
RisingDownloader.Waski!1.A489 (CLASSIC)
TACHYONTrojan-PWS/W32.LdPinch.39692
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Spy.Zbot.gdb
DrWebTrojan.DownLoader10.51280
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_UPATRE.SMJ7
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan/PSW.LdPinch.adnc
VaristW32/Zbot.AEY.gen!Eldorado
AviraTR/Spy.Zbot.gdb
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Zbot.HBAI!MTB
XcitiumTrojWare.Win32.Kryptik.BFP@54u2z9
ArcabitTrojan.Ppatre.Gen.1
SUPERAntiSpywareTrojan.Agent/Gen-Email
ZoneAlarmTrojan-PSW.Win32.LdPinch.hij
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win.LdPinch.C5600374
Acronissuspicious
BitDefenderThetaAI:Packer.FA70625E1F
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
VBA32BScope.TrojanPSW.LdPinch
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMJ7
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.PWS.LdPinch!xWvTXkeY8jg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/ZBot.GDB!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[stealer]:Win/Zbot.HBAI!MTB

How to remove Win32/Kryptik.BPMF?

Win32/Kryptik.BPMF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment