Malware

How to remove “Win32/Kryptik_AGen.BGU”?

Malware Removal

The Win32/Kryptik_AGen.BGU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik_AGen.BGU virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik_AGen.BGU?


File Info:

name: BD423E5034295209CC92.mlw
path: /opt/CAPEv2/storage/binaries/d08cf654adfbb283f67df1b17cbbbfbd112a6ae449d4a81fd1276b7577186946
crc32: 78A0AC8C
md5: bd423e5034295209cc92912c549908fe
sha1: d7c47c9640d5f98fb3a0c3092f4d6ef380af7fac
sha256: d08cf654adfbb283f67df1b17cbbbfbd112a6ae449d4a81fd1276b7577186946
sha512: f54f136200230cb629634b23cb94c8822ffa42f36d05bdc91d9e088b553d3e303a282df30e7a1c67c7bed2db2221ebb6f4c37a5691c6f81587dff0e7746ab397
ssdeep: 12288:Bm2YgQVIc8hKV1EvoKlSql4ejAAWxe1X7BMPpqeepz4eeriQ/ANBu:Bk9eKLEvoKlSql4ejrWx4X7BMPpqeepY
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16D945E2FB7480B76CEC10BB22E0E58C6B7299579237985F03468805D1277E6B93BF794
sha3_384: 2983f79d6f653a14b2494448819d9195c04747a11ed4b1614882d3764ad6ca2f8755839908ab98a4f2e7af52dcdcca7c
ep_bytes: 5fefdf6d0f865bea0a67527b18253ac1
timestamp: 1974-02-09 00:00:00

Version Info:

0: [No Data]

Win32/Kryptik_AGen.BGU also known as:

LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.123
MicroWorld-eScanTrojan.GenericKDZ.98614
FireEyeGeneric.mg.bd423e5034295209
ALYacTrojan.GenericKDZ.98614
MalwarebytesFakeAlert.Trojan.Downloader.DDS
ZillyaTrojan.Copak.Win32.172544
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a45ef1 )
K7GWTrojan ( 005a45ef1 )
Cybereasonmalicious.640d5f
BitDefenderThetaGen:NN.ZexaF.36196.A8Z@aWtKiWn
CyrenW32/Kryptik.JCS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik_AGen.BGU
APEXMalicious
ClamAVWin.Packed.Lazy-10001745-0
KasperskyUDS:Trojan.Win32.Copak
BitDefenderTrojan.GenericKDZ.98614
NANO-AntivirusTrojan.Win32.Selfmod.jvyqig
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gifya
EmsisoftTrojan.GenericKDZ.98614 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.GenericKDZ.98614
McAfee-GW-EditionBehavesLike.Win32.Ctsinf.gh
Trapminemalicious.high.ml.score
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1TCDDYM
JiangminTrojan.Generic.gljas
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik.GIRH
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Generic.D18136
ZoneAlarmUDS:Trojan.Win32.Copak
MicrosoftTrojan:Win32/Glupteba.MT!MTB
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.FJB.R567349
McAfeePacked-FJB!BD423E503429
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan-Downloader.Win32.FakeAlert
MaxSecureTrojan.Malware.206058672.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik_AGen.BGU?

Win32/Kryptik_AGen.BGU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment