Malware

Win32/Kryptik_AGen.BGD removal instruction

Malware Removal

The Win32/Kryptik_AGen.BGD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGD virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik_AGen.BGD?


File Info:

name: 5F343FE8CC487F121661.mlw
path: /opt/CAPEv2/storage/binaries/897b2827fc3363049618156408be9293d765cb54e6ccd4c2b4e8bbf0b2480103
crc32: 06B7FD93
md5: 5f343fe8cc487f1216611d0b64825965
sha1: c85d73b97a913052835d0a123e5a371de773b172
sha256: 897b2827fc3363049618156408be9293d765cb54e6ccd4c2b4e8bbf0b2480103
sha512: d5e5d1ea5e3c2ef01d54fe8ed33ec183ff13df5c008862e4f241ec5c3e249950f632e1db71db90ebc822d6dbce4a96e5ee10697ee830f604eb52d241c6caa4fb
ssdeep: 24576:Rzr3pcrBkrvWWoVwuM3XYFa/ZSCBHn67c:Rzr3mrGhz4FgVBHn64
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14315CEDC13108D57CC896AB6B83DADA96621683DD7C2D331326CF2CFB9253D4654BA38
sha3_384: ce43caa7274c4645a8311e91fce40e19c83a36b02995ee9a22b08885ceb649eea19450b1a8d2d0e15b92a6463c1ba88e
ep_bytes: c2384cd19251c85697b0c1c715faa97d
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGD also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.Tool.dc
ALYacTrojan.GenericKDZ.104849
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
BitDefenderTrojan.GenericKDZ.104849
K7GWTrojan ( 005a15b21 )
Cybereasonmalicious.97a913
ArcabitTrojan.Generic.D19991
BitDefenderThetaGen:NN.ZexaF.36744.68Y@a84aMOh
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik_AGen.BGD
APEXMalicious
ClamAVWin.Packed.Razy-9836307-0
KasperskyVHO:Trojan.Win32.Khalesi.gen
NANO-AntivirusTrojan.Win32.Agent.imlpvf
MicroWorld-eScanTrojan.GenericKDZ.104849
TencentTrojan.Win32.Selfmod.ka
EmsisoftTrojan.GenericKDZ.104849 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
VIPRETrojan.GenericKDZ.104849
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.5f343fe8cc487f12
SophosTroj/Agent-BFEY
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.cypp
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Kryptik.gify
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
MicrosoftTrojan:Win32/Cerber.MPI!MTB
ZoneAlarmVHO:Trojan.Win32.Khalesi.gen
GDataWin32.Trojan.PSE.1B28NHU
VaristW32/Trojan.MJSE-7842
AhnLab-V3Packed/Win.FJB.R622264
Acronissuspicious
McAfeeTrojan-FVOQ!5F343FE8CC48
TACHYONTrojan/W32.Selfmod
DeepInstinctMALICIOUS
VBA32Trojan.Copak
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik_AGen.BGD?

Win32/Kryptik_AGen.BGD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment