Malware

Win32/Kryptik_AGen.BGD removal tips

Malware Removal

The Win32/Kryptik_AGen.BGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGD virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik_AGen.BGD?


File Info:

name: A2F7A173284D0CF8B0A0.mlw
path: /opt/CAPEv2/storage/binaries/0d4a3af25984302e21e9d8f792e37bc9abf32b033c3fe85632191f2a4b6d0440
crc32: A5164D6F
md5: a2f7a173284d0cf8b0a08e7d34664682
sha1: 18e1379fa34d33b97cd84312625d3c9972493b06
sha256: 0d4a3af25984302e21e9d8f792e37bc9abf32b033c3fe85632191f2a4b6d0440
sha512: d1a4beeba11e7bec56d6427c80867618bbf5141f2e36e97d615290b64f07aab2f4dcb17caa7fdff01e9d478d206bce99f3053f0b96c48d9bb1fb89ca3d589b65
ssdeep: 12288:y25IFQuQsCcfxlFtX+6VQ5zCD4VZRDGWF1m3aYhOA6eXV:yCuQZZcfxlm6VQ5zY431CaYAeXV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CEC4BEA9FCAF4A91CCEF7CB717F1B041A1F2D25A0FAB40C5EA6950256C32B90743459E
sha3_384: 0548136983eee80ac28124ff849703121d5e21d3a5e8d992b944ef3b6f47fd1a88edc99a103fd80f6b7e9ad31e5172c8
ep_bytes: dad568cc8abcec4b8f5de5da9d1f8d60
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGD also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.98614
SkyhighBehavesLike.Win32.RAHack.hc
McAfeeTrojan-FVOQ!A2F7A173284D
MalwarebytesCrypt.Trojan.MSIL.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.fa34d3
ArcabitTrojan.Generic.D18136
BitDefenderThetaGen:NN.ZexaF.36680.K8Z@a8s1DTi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9828382-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKDZ.98614
NANO-AntivirusTrojan.Win32.PackedDownloader.ijxqni
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Copak.hn
EmsisoftTrojan.GenericKDZ.98614 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPRETrojan.GenericKDZ.98614
SophosTroj/Agent-BFEY
IkarusTrojan-Downloader.Win32.FakeAlert
JiangminTrojan.Copak.czfo
VaristW32/Trojan.NJGF-3047
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.PSE.11XGYE9
GoogleDetected
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
VBA32Trojan.Khalesi
ALYacTrojan.GenericKDZ.98614
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik_AGen.BGD?

Win32/Kryptik_AGen.BGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment