Malware

Win32/Kryptik.BSMF removal guide

Malware Removal

The Win32/Kryptik.BSMF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BSMF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Starts servers listening on 0.0.0.0:39739, 127.0.0.1:22706, :0
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to stop active services
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Creates Zeus (Banking Trojan) mutexes
  • Zeus P2P (Banking Trojan)
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

tonnymaxgroup.com

How to determine Win32/Kryptik.BSMF?


File Info:

crc32: 67BC7C83
md5: c7947030cbb4393682dab0b988907413
name: C7947030CBB4393682DAB0B988907413.mlw
sha1: f2ecc44fb6e17b363c5d7c170e090d597de8b9a2
sha256: 7ed42c04dc11c8d8dcabf77fa1c71a760f064146f1dd7364b5d413783f2588c5
sha512: 5cad9237efb95e6ea10a172bfdc507d08bca200b8b9ab382d944ea60556fcfca1125ffde87b4e1f06d2da83589f0ef3596123c0662f3f5866edd49a50b57d252
ssdeep: 6144:Kj3kwFIJnGCj+NMiZK1m8X63wAODTUj4CAslUtVVt15IYGAHSHwMudAEtI:Ckt3j+eEdA63w5TCAslWEYxYNuNI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.BSMF also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lWdh
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Ransom.Seven.17
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2587141
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Kryptik.5b534df7
K7GWTrojan ( 0055dd191 )
K7AntiVirusTrojan ( 0055dd191 )
SymantecInfostealer.Napolar
ESET-NOD32a variant of Win32/Kryptik.BSMF
AvastWin32:Crypt-ROG [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Seven.17
NANO-AntivirusTrojan.Win32.Zbot.cwfcjy
MicroWorld-eScanGen:Variant.Ransom.Seven.17
TencentMalware.Win32.Gencirc.114c3ffb
Ad-AwareGen:Variant.Ransom.Seven.17
SophosMal/Zbot-OA
BitDefenderThetaGen:NN.ZexaF.34142.wqZ@ai57Htgb
VIPRETrojan.Win32.Fareit.if (v)
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.c7947030cbb43936
EmsisoftGen:Variant.Ransom.Seven.17 (B)
JiangminTrojanSpy.Zbot.ecbb
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.71A522
KingsoftWin32.Troj.Zbot.rf.(kcloud)
MicrosoftPWS:Win32/Zbot!CI
ArcabitTrojan.Ransom.Seven.17
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Seven.17
AhnLab-V3Spyware/Win32.Zbot.R96672
Acronissuspicious
McAfeeArtemis!C7947030CBB4
MAXmalware (ai score=85)
VBA32SScope.Malware-Cryptor.Hlux
PandaTrj/CI.A
IkarusTrojan-Spy.Zbot
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.WIF!tr
AVGWin32:Crypt-ROG [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.BSMF?

Win32/Kryptik.BSMF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment