Malware

Win32/Kryptik_AGen.BGD (file analysis)

Malware Removal

The Win32/Kryptik_AGen.BGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGD virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik_AGen.BGD?


File Info:

name: 1B78685E0B4F539C4CE0.mlw
path: /opt/CAPEv2/storage/binaries/2022dd624a717d33d06586f677d86d10530a3577ed7bb4c48632b6cee39c2095
crc32: DA650C75
md5: 1b78685e0b4f539c4ce0b1d956a72be1
sha1: e911ffd31144b4a5fb3cc5385c6197a6fb49dadf
sha256: 2022dd624a717d33d06586f677d86d10530a3577ed7bb4c48632b6cee39c2095
sha512: 04dc320304182e3dc9686f5d2c5438d914ab4653680e8c42a31097c5f4d9eb932deafc53f2cc2b514b784e0dbfc9bfbd0d484dc5ed07428ad44d9725d0ec14b8
ssdeep: 24576:I2ZLWri90Dryy/zuvT2YEqWa/ZSCBHn67c:I2dt0DBuvT2YjWgVBHn64
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16C15C09D13A25687E60C57F96C6E9E75C4329E78BB13CA7DB008B25734687C2C326E31
sha3_384: eacd7ba62dfc2146f37ba2c5a34db6016d78324b78bb6750a22c7aaf3a3023f1480713ff8a3f8338a48ae0521c841ec0
ep_bytes: a3b30b7af3da8ffdf63b866c7471eed6
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGD also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.104139
FireEyeGeneric.mg.1b78685e0b4f539c
SkyhighBehavesLike.Win32.Generic.dc
McAfeeTrojan-FVOQ!1B78685E0B4F
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a15b21 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D196CB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGD
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Razy-9836307-0
KasperskyVHO:Trojan.Win32.Khalesi.gen
BitDefenderTrojan.GenericKDZ.104139
NANO-AntivirusTrojan.Win32.Agent.imlpvf
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Selfmod.ka
SophosTroj/Agent-BFEY
F-SecureHeuristic.HEUR/AGEN.1368582
VIPRETrojan.GenericKDZ.104139
EmsisoftTrojan.GenericKDZ.104139 (B)
IkarusTrojan-Downloader.Win32.FakeAlert
JiangminTrojan.Copak.cypp
VaristW32/Trojan.MJSE-7842
AviraHEUR/AGEN.1368582
Antiy-AVLTrojan/Win32.Kryptik.gify
Kingsoftmalware.kb.a.979
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Cerber.MPI!MTB
ZoneAlarmVHO:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.PSE.1B28NHU
GoogleDetected
AhnLab-V3Packed/Win.FJB.R622264
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.68Y@a84aMOh
ALYacTrojan.GenericKDZ.104139
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Copak
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.31144b
DeepInstinctMALICIOUS

How to remove Win32/Kryptik_AGen.BGD?

Win32/Kryptik_AGen.BGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment