Malware

About “Win32/Kryptik_AGen.BGD” infection

Malware Removal

The Win32/Kryptik_AGen.BGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik_AGen.BGD?


File Info:

name: B229082EA8B8E71D194F.mlw
path: /opt/CAPEv2/storage/binaries/344f1ffccdab2e1c92eb012c9167940e3f117f3e55aae1b4b1f1a2d945b8ca25
crc32: 6A4C2E82
md5: b229082ea8b8e71d194f36def7933536
sha1: 7113d770b8da94d27c4bb375020f8fdf38bcd991
sha256: 344f1ffccdab2e1c92eb012c9167940e3f117f3e55aae1b4b1f1a2d945b8ca25
sha512: 6a28c8baded759c1732599a750fc0b04d7946ebf720dca6eab5055cb02293d9c95e3584e0587e1d2665bd22b2bb54b5cc7a3a887650556c537140c598a09d78c
ssdeep: 12288:FQa76KNRRXlGLJ/TK6VQ5zCD4VZRDGWF1m3aYhOA6eXV:NNRRVGLJ7K6VQ5zY431CaYAeXV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T132C49CADFC4B7A50CCEBB87B1DB27CD4B5CE934E0FAA414CFA6511662C35880B1614DA
sha3_384: 735e5a17fbf789d3650b21587cde28a4c57d39e941c1c39cca5a2aaf0e3883c24917de8be8ea2fcafca93d38cece2f3b
ep_bytes: 8b104bdedb79cf59de98c6c8ccdaae72
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGD also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.98614
SkyhighBehavesLike.Win32.RAHack.hc
McAfeeTrojan-FVOQ!B229082EA8B8
MalwarebytesCrypt.Trojan.MSIL.DDS
ZillyaTrojan.Kryptik.Win32.4495426
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.ea8b8e
BitDefenderThetaGen:NN.ZexaF.36802.K8Z@a8s1DTi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGD
APEXMalicious
ClamAVWin.Packed.Razy-9828382-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKDZ.98614
NANO-AntivirusTrojan.Win32.PackedDownloader.ijxqni
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Kryptik.hdb
TACHYONTrojan/W32.Selfmod
SophosTroj/Agent-BFEY
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPRETrojan.GenericKDZ.98614
FireEyeGeneric.mg.b229082ea8b8e71d
EmsisoftTrojan.GenericKDZ.98614 (B)
IkarusTrojan-Downloader.Win32.FakeAlert
JiangminTrojan.Copak.czfo
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Trojan.NJGF-3047
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Glupteba.MT!MTB
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D18136
GDataWin32.Trojan.PSE.11XGYE9
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.R636531
Acronissuspicious
VBA32Trojan.Khalesi
ALYacTrojan.GenericKDZ.98614
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudVirTool:Win/Kryptik.GIRH

How to remove Win32/Kryptik_AGen.BGD?

Win32/Kryptik_AGen.BGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment