Malware

Win32/Kryptik_AGen.BGD malicious file

Malware Removal

The Win32/Kryptik_AGen.BGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik_AGen.BGD?


File Info:

name: 78BEBBE8A8EF3C6219FF.mlw
path: /opt/CAPEv2/storage/binaries/58c0e3c691d2f98a0a4770d4c067d702141b4e2830e0ed3498331fc42bf48558
crc32: 14C3B632
md5: 78bebbe8a8ef3c6219ff0a5d21f9d6e2
sha1: 5ffafad902d1c726be4931cd98cb262f862a9f5b
sha256: 58c0e3c691d2f98a0a4770d4c067d702141b4e2830e0ed3498331fc42bf48558
sha512: 5a5a50c4deb71b94b317c5c20ec77e647aaaec3677cb4ed319083146bff53dd82cdc5e99d204c0061949f8be127053130784f52ca7ff72a4e0ad0964e0a3cd6f
ssdeep: 12288:1A5WFvHU8FHkVOBt6VQ5zCD4VZRDGWF1m3aYhOA6eXV:e5WFvHrFHOOt6VQ5zY431CaYAeXV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T169C48CAFFFFF7A50CCAB78373CB1644191AEF18E4E6E0884D954516C2C75C84B2644AA
sha3_384: 9b89bf40304961bb416439a0e82a60efe33cd87cc86c24b78bac00f7b619b5f7df8b3f67cdaa1dafe0e36676bb358e5a
ep_bytes: c1c18ffb91a80b7c944902ed860b6a57
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGD also known as:

BkavW32.AIDetectMalware
DrWebTrojan.PackedENT.147
MicroWorld-eScanTrojan.GenericKDZ.98614
SkyhighBehavesLike.Win32.Generic.hc
McAfeeTrojan-FVOQ!78BEBBE8A8EF
MalwarebytesCrypt.Trojan.MSIL.DDS
ZillyaTrojan.Kryptik.Win32.4495426
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.K8Z@a8s1DTi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGD
APEXMalicious
ClamAVWin.Packed.Razy-9828382-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKDZ.98614
NANO-AntivirusTrojan.Win32.Kryptik.fgyyhy
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Copak.hn
EmsisoftTrojan.GenericKDZ.98614 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
VIPRETrojan.GenericKDZ.98614
FireEyeGeneric.mg.78bebbe8a8ef3c62
SophosTroj/Agent-BFEY
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
GDataWin32.Trojan.PSE.11XGYE9
JiangminTrojan.Copak.czfo
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
VaristW32/Trojan.NJGF-3047
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D18136
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
VBA32Trojan.Khalesi
ALYacTrojan.GenericKDZ.98614
TACHYONTrojan/W32.Selfmod
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Kryptik_AGen.BGD?

Win32/Kryptik_AGen.BGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment