Malware

Win32/Kryptik.BZEQ information

Malware Removal

The Win32/Kryptik.BZEQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BZEQ virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.BZEQ?


File Info:

name: 9A006D40B05777AFF98C.mlw
path: /opt/CAPEv2/storage/binaries/374571c4384a522f4f87e4d4f3798dd253989789af5de199a01fe8b6063d9e63
crc32: 9D0640E8
md5: 9a006d40b05777aff98c57556e47c3d8
sha1: 849b47717f1d24ac77d3d13d4fdd6750f4b8b989
sha256: 374571c4384a522f4f87e4d4f3798dd253989789af5de199a01fe8b6063d9e63
sha512: a966aa6b08c5db68e465d93dbb84e4d7443da2591f609b26b742a933002faaecdf145fbc072e5704abfd14e0682ad6ef2283454e61037f4fc7cdc51ef11cbd6e
ssdeep: 192:mmS3adxz0dXd6jzmzVUdd1Bv4D95DkufSZSfG0CYmt5PMVVVfGtBU8:mr0xz6NjVUdN4D9x76YLCDkHutB9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163C2AB6126C506A5D263BA713CAEC6F54452BD2F7F0F060FDB43FE2D0783231698A956
sha3_384: 5b5f2a56a040dcc05b5682764df3eb2464b4cd0932c980e37f7163a098dfe74f9fe742ef7ef1a907d4ff9e81224275a4
ep_bytes: 558bec83c4dc8d4ddc51ff1530304000
timestamp: 2013-07-15 03:06:52

Version Info:

0: [No Data]

Win32/Kryptik.BZEQ also known as:

BkavW32.FamVT.GeND.Trojan
AVGWin32:Agent-AUID [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JQNN
SkyhighBehavesLike.Win32.PWSZbot.mm
McAfeeBackDoor-FBYB!9A006D40B057
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7GWTrojan-Downloader ( 0040f7f11 )
K7AntiVirusTrojan-Downloader ( 0040f7f11 )
BitDefenderThetaGen:NN.ZexaF.36802.buX@aqIqtvdi
VirITTrojan.Win32.Crypt_s.GHA
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BZEQ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Upatre-10025078-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JQNN
NANO-AntivirusTrojan.Win32.DownLoad3.cwgize
AvastWin32:Agent-AUID [Trj]
TencentTrojan-DL.Win32.Waski.hn
EmsisoftTrojan.Downloader.JQNN (B)
BaiduWin32.Trojan-Downloader.Waski.a
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.28161
VIPRETrojan.Downloader.JQNN
TrendMicroTROJ_UPATRE.SMJ9
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.9a006d40b05777af
SophosMal/Upatre-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.azsjp
VaristW32/Trojan.CVPW-4098
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Downloader]/Win32.Waski
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Trickbot.GML!MTB
XcitiumTrojWare.Win32.Bublik.S@59hfrj
ArcabitTrojan.Downloader.JQNN
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Downloader.JQNN
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5599882
Acronissuspicious
VBA32BScope.Trojan.Download
ALYacTrojan.Downloader.JQNN
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_UPATRE.SMJ9
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!pRoVF8iDuYU
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.GQIX!tr
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.BZEQ?

Win32/Kryptik.BZEQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment