Malware

Win32/Kryptik.BVCA malicious file

Malware Removal

The Win32/Kryptik.BVCA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BVCA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.BVCA?


File Info:

name: 9D5D4E4FA7E23D4705AD.mlw
path: /opt/CAPEv2/storage/binaries/86a0e374a1d35a147f1883c833171e9497c1b43b5e1516a68c8c9a443d049fae
crc32: 52F6D079
md5: 9d5d4e4fa7e23d4705ad77de69798c80
sha1: 20a34f81487ced5ce1fee6b841ac2cb6bee0a8ae
sha256: 86a0e374a1d35a147f1883c833171e9497c1b43b5e1516a68c8c9a443d049fae
sha512: 4e5de780652ae08d33d821732f8f89025858d215e7134495bf9f4576ca9432ef2c5dbb861b1e4cdf436e26d14b1e3dbc7c399bdeb3a19120cb90308ac96ea64c
ssdeep: 3072:ujjjjjjjjjK9cu8fpVN1e7ZcSCaVu1nu3ZCHVwS5gwUqAG:N9f8RVN1e7ZcSCt1nup0p1A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AEF3181AF9B89A25C05D4470491385F41835BF20BB20B25B7DFEFA9EF8742B0E6246DD
sha3_384: 549db072bc3b31ff3a6fc1a52c5ef4ed39590ddedbcd82ba1a5218e10745306ddad4c54c63d8cd745cd3f5d81597cfab
ep_bytes: 558bec83ec48a10ce04100a3a80c4200
timestamp: 2014-02-14 13:31:25

Version Info:

0: [No Data]

Win32/Kryptik.BVCA also known as:

BkavW32.AIDetectMalware
AVGWin32:BotX-gen [Trj]
tehtrisGeneric.Malware
DrWebBackDoor.Kuluoz.4
MicroWorld-eScanGen:Variant.Ransom.TorrentLocker.92
CAT-QuickHealTrojanDownloader.Kuluoz.D3
SkyhighBehavesLike.Win32.Pate.cm
McAfeeBackDoor-FBTK!9D5D4E4FA7E2
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ransom.TorrentLocker.92
SangforTrojan.Win32.Save.a
K7AntiVirusBackdoor ( 0040f7921 )
AlibabaTrojanDropper:Win32/dropper.ali1003001
K7GWBackdoor ( 0040f7921 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36802.kmW@aWvA5Znc
VirITBackdoor.Win32.Generic.PYV
SymantecPacked.Generic.459
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BVCA
CynetMalicious (score: 99)
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Trojan.Sirefef-5921
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.TorrentLocker.92
NANO-AntivirusTrojan.Win32.Androm.ctojck
TencentMalware.Win32.Gencirc.10b89c66
EmsisoftGen:Variant.Ransom.TorrentLocker.92 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
ZillyaBackdoor.Androm.Win32.6197
TrendMicroTROJ_KULUOZ.SMRF
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.9d5d4e4fa7e23d47
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Androm.ccp
VaristW32/Trojan.PJZZ-5409
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Androm
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojanDownloader:Win32/Kuluoz.D
XcitiumTrojWare.Win32.Kryptik.BVPL@57uzhp
ArcabitTrojan.Ransom.TorrentLocker.92
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.TorrentLocker.92
GoogleDetected
AhnLab-V3Trojan/Win32.ZeroAccess.C260364
VBA32BScope.Backdoor.Kuluoz
ALYacGen:Variant.Ransom.TorrentLocker.92
TACHYONBackdoor/W32.Androm.164864.B
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KULUOZ.SMRF
RisingMalware.FakeXLS/ICON!1.9C3D (CLASSIC)
IkarusTrojan-Dropper.Win32.Injector
MaxSecureTrojan.Malware.6894110.susgen
FortinetW32/GenKryptik.ATAM!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/TorrentLocker

How to remove Win32/Kryptik.BVCA?

Win32/Kryptik.BVCA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment