Malware

Win32/Kryptik_AGen.BGD removal tips

Malware Removal

The Win32/Kryptik_AGen.BGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik_AGen.BGD?


File Info:

name: 12FB91524009F2937E43.mlw
path: /opt/CAPEv2/storage/binaries/ec4d15228d1f7d17f59e43cdc65ea35a4ba690f82431a05a4ba75347ce902266
crc32: 48EA12EB
md5: 12fb91524009f2937e43c5c0869ea1da
sha1: f89f7c10bf01e870452ceaca47a58cbc9039be92
sha256: ec4d15228d1f7d17f59e43cdc65ea35a4ba690f82431a05a4ba75347ce902266
sha512: e7006c71cf85e7cb701ecffe9b1439b07647113cbfaaa2db682f765730caa3bffcf1ee30c6f4566a94daf24d65f14639442a6c73ddcc2b4110f42383b6f78975
ssdeep: 24576:S6JiyCVbybZJRgpg/5znQbbosO16uupa/ZSCBHn67c:pCVbcJ+CpIY6VpgVBHn64
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19C15D11C33968913C4516272C95EDA760211AE7DBD63C27ABA803F4F7EB5FA1C50BA34
sha3_384: b73dd3d8f917373dbdced3ad87dafbc6bd4b31552a19e23adb19d9325b6b6cb4e78fde05aeeeb7f320bcf92a60ec73e8
ep_bytes: bd8677c7edeff340e80efad16a44926b
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGD also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.104139
SkyhighBehavesLike.Win32.PWSZbot.dc
McAfeePacked-FJB!12FB91524009
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a15b21 )
Cybereasonmalicious.0bf01e
ArcabitTrojan.Generic.D196CB
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9836307-0
KasperskyVHO:Trojan.Win32.Khalesi.gen
BitDefenderTrojan.GenericKDZ.104139
NANO-AntivirusTrojan.Win32.Agent.imlpvf
AvastWin32:Evo-gen [Trj]
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SophosTroj/Agent-BFEY
F-SecureTrojan.TR/Crypt.XPACK.Gen2
VIPRETrojan.GenericKDZ.104139
EmsisoftTrojan.GenericKDZ.104139 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cypp
VaristW32/Trojan.MJSE-7842
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.984
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Cerber.MPI!MTB
ZoneAlarmVHO:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.PSE.1B28NHU
GoogleDetected
AhnLab-V3Packed/Win.FJB.R622264
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.68Y@a84aMOh
TACHYONTrojan/W32.Selfmod
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TencentTrojan.Win32.Selfmod.ka
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik_AGen.BGD?

Win32/Kryptik_AGen.BGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment