Malware

How to remove “Win32/Kryptik_AGen.BGD”?

Malware Removal

The Win32/Kryptik_AGen.BGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGD virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik_AGen.BGD?


File Info:

name: 69116789D717BE2B9C02.mlw
path: /opt/CAPEv2/storage/binaries/4a943260055aff058b922c9990fbf7a72e9bd379b706bbf954ee83243aec9310
crc32: 8EBC6C93
md5: 69116789d717be2b9c025d5db0fcfff9
sha1: c5562748c2394a42b1a5fb97c712b3951549aa38
sha256: 4a943260055aff058b922c9990fbf7a72e9bd379b706bbf954ee83243aec9310
sha512: f65f4e874f254e30ee78e008724ac72445cd271b29fb74cd4ca42fdd9709897abc2e9459603e2262cf648b38411a99f0eb6dc1b7a1a429fdb21d0821c64db46a
ssdeep: 12288:JPx5ai9dsNDIlCig2g5nuFQZ7u1MoSuwBl6VQ5zCD4VZRDGWF1m3K:zcvDdl6VQ5zY431CK
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1FAA48CACFC4F4FB0CC9B7F37C4B16C81C4D2A6464FAA1D84FB6541E52D26988B12E496
sha3_384: 220683ed6685f7977a53278d2ad3be044236f3d5d4163ed102473153934fd5c8c527168e8f27f92f967253aeaff32fdf
ep_bytes: 1075c62a401c42ad45fd4b3c57bf2386
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGD also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.98614
ClamAVWin.Packed.Razy-9828382-0
FireEyeGeneric.mg.69116789d717be2b
SkyhighBehavesLike.Win32.RAHack.gc
McAfeeTrojan-FVOQ!69116789D717
MalwarebytesCrypt.Trojan.MSIL.DDS
VIPRETrojan.GenericKDZ.98614
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D18136
BitDefenderThetaGen:NN.ZexaF.36744.C8Z@a8s1DTi
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik_AGen.BGD
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderTrojan.GenericKDZ.98614
NANO-AntivirusTrojan.Win32.PackedDownloader.ijxqni
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Copak.hn
EmsisoftTrojan.GenericKDZ.98614 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.Kryptik.Win32.4495426
SophosTroj/Agent-BFEY
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.czfo
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Kryptik.girh
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Glupteba.MT!MTB
ZoneAlarmVHO:Trojan.Win32.Copak.gen
GDataWin32.Trojan.PSE.11XGYE9
VaristW32/Trojan.NJGF-3047
AhnLab-V3Packed/Win.FJB.C5394144
Acronissuspicious
ALYacTrojan.GenericKDZ.98614
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.BF57 (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.8c2394
DeepInstinctMALICIOUS

How to remove Win32/Kryptik_AGen.BGD?

Win32/Kryptik_AGen.BGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment