Malware

Win32/Kryptik.BZGE removal tips

Malware Removal

The Win32/Kryptik.BZGE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BZGE virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.BZGE?


File Info:

name: C7E1B45661166F1E49D2.mlw
path: /opt/CAPEv2/storage/binaries/ec77f1f3b3fca1b562cdb59ec33ef2e371731d54e428e902288368fc13d00d0a
crc32: 479F86AD
md5: c7e1b45661166f1e49d211aed8b146df
sha1: 2caa4350fe98939dcecf072ecfc205053097a6a5
sha256: ec77f1f3b3fca1b562cdb59ec33ef2e371731d54e428e902288368fc13d00d0a
sha512: e6f1fb7120a9f6dee263b61a5c70620d221d3d023ce430ef4dd0bcbcaaa98fe21ec0a7ab964181af616885d8e7422a2dd0a5b4c54e3b5dd1adb45fdfeff73c41
ssdeep: 384:4gNT1I08U8JTmDjcIBNy5IF5tuUS6caUBdDBesL+:tT171CTcj5BI5+QUS6GBg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16482E6FD5AC19633C2B3C5718CBEC4D67826BD133A055D2D64DA7F0A8833A8279A152F
sha3_384: ab99974db485183e4bc589c11387ebf01713fc952c430d6c0abf751dd700a86605b1fdd1761bc4a50fa41775c5b524a2
ep_bytes: 60be006040008dbe00b0ffff5783cdff
timestamp: 2014-04-07 20:13:23

Version Info:

0: [No Data]

Win32/Kryptik.BZGE also known as:

BkavW32.AIDetectMalware
AVGWin32:Agent-AUYG [Trj]
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Application.Symmi.42813
FireEyeGeneric.mg.c7e1b45661166f1e
CAT-QuickHealTrojanDwnldr.Upatre.MUE.A4
SkyhighBehavesLike.Win32.PolyPatch.lh
McAfeeGenericRXAA-FA!C7E1B4566116
Cylanceunsafe
ZillyaTrojan.Kryplod.Win32.11
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
AlibabaTrojanDownloader:Win32/Upatre.4ccf587b
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.bmHfaS42j3gi
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.BZGE
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Ag-1
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderGen:Variant.Application.Symmi.42813
NANO-AntivirusTrojan.Win32.Crypted.cwgtvo
AvastWin32:Agent-AUYG [Trj]
TencentTrojan-DL.Win32.Upatre.kz
TACHYONTrojan-Spy/W32.ZBot.22480.B
EmsisoftGen:Variant.Application.Symmi.42813 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.DownLoader11.34259
VIPREGen:Variant.Application.Symmi.42813
TrendMicroTROJ_UPATRE.SMN3
Trapminesuspicious.low.ml.score
SophosMal/Zbot-PY
IkarusTrojan-Downloader.Win32.Upatre
JiangminTrojanSpy.Zbot.eeeh
VaristW32/Kryptik.MAH.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.b.972
MicrosoftTrojan:Win32/Phonzy.A!ml
GridinsoftRansom.Win32.Zbot.sa
XcitiumTrojWare.Win32.Spy.Zbot.stev@5fz0j3
ArcabitTrojan.Application.Symmi.DA73D
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan.PSE.105DUIZ
GoogleDetected
AhnLab-V3Trojan/Win32.Upatre.C3058566
Acronissuspicious
ALYacGen:Variant.Application.Symmi.42813
MAXmalware (ai score=73)
VBA32TrojanSpy.Zbot
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SMN3
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!An7rpyXENxg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr.dldr
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Zbot.SD!MTB

How to remove Win32/Kryptik.BZGE?

Win32/Kryptik.BZGE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment