Malware

Win32:Crypt-PGA [Trj] malicious file

Malware Removal

The Win32:Crypt-PGA [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Crypt-PGA [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32:Crypt-PGA [Trj]?


File Info:

name: 5FDB677995293A1BB2A7.mlw
path: /opt/CAPEv2/storage/binaries/c11db9d1b3369d5af0536b4e4864a6346309a3ca61e35b3bad727c8cabc3a9eb
crc32: 4157684D
md5: 5fdb677995293a1bb2a76582064adf50
sha1: fe07073ce52b26b8d81151b4f4fd0e3f5882483a
sha256: c11db9d1b3369d5af0536b4e4864a6346309a3ca61e35b3bad727c8cabc3a9eb
sha512: f8379929a834805a4fde439b000ab055bf07ecf2dbdaacaaaec22ddc0f1841ee4f66aa960e3e798955c557036de4dc988be64ce64314915e091ba3554dc48abd
ssdeep: 24576:4ijWtRH8WMmjB21PeSW9qs/InAwlhYAHej:4ij4Rc4j4kSWl/I/zDH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152053391E1A819B1DC84CDFB76ABF5A14707DE80AC48A41C6ED4D546FDFB8CC02AD21E
sha3_384: 41b48f995226220eb80f4db37c1912f48bd3ff29847ed739749f4ba56bb04e7f87be899485ca558c8726145d52b02b52
ep_bytes: be042140002bc983ee6e8b068bf0648b
timestamp: 2013-03-24 18:05:55

Version Info:

0: [No Data]

Win32:Crypt-PGA [Trj] also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lJbY
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.VIZ.Gen.1
ClamAVWin.Trojan.Tepfer-61
FireEyeGeneric.mg.5fdb677995293a1b
McAfeeBackDoor-FATM!5FDB67799529
MalwarebytesTrojan.MalPack
ZillyaTrojan.Kryptik.Win32.828423
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f49f1 )
AlibabaVirTool:Win32/Obfuscator.c6422c8d
K7GWTrojan ( 0040f49f1 )
Cybereasonmalicious.ce52b2
VirITTrojan.Win32.X-Agent.BT
CyrenW32/FakeAlert.YX.gen!Eldorado
SymantecPacked.Generic.402
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BBFK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.Tepfer.bqwiko
AvastWin32:Crypt-PGA [Trj]
TencentWin32.Trojan.Generic.Vylw
SophosMal/EncPk-AKP
F-SecureTrojan.TR/Buzus.819712548
DrWebBackDoor.SlymENT.1498
VIPRETrojan.VIZ.Gen.1
TrendMicroTROJ_FAKEAV.SMIM
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.cc
Trapminemalicious.high.ml.score
EmsisoftTrojan.VIZ.Gen.1 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.VIZ.Gen.1
JiangminTrojan.Generic.hzrk
WebrootW32.Trojan.Gen
AviraTR/Buzus.819712548
Antiy-AVLTrojan[PSW]/Win32.Tepfer
XcitiumTrojWare.Win32.Kryptik.BAWW@4xecqg
ArcabitTrojan.VIZ.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/Obfuscator.ARL
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R66408
BitDefenderThetaGen:NN.ZexaF.36662.YuW@aqI8Tzcc
ALYacTrojan.VIZ.Gen.1
MAXmalware (ai score=100)
VBA32Heur.Trojan.Hlux
Cylanceunsafe
PandaTrj/Tepfer.B
TrendMicro-HouseCallTROJ_FAKEAV.SMIM
RisingBackdoor.Agent!1.6976 (CLASSIC)
YandexTrojan.GenAsa!Bw6PmjL12+o
IkarusVirus.Agent
FortinetW32/Kryptik.AXUE!tr
AVGWin32:Crypt-PGA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:Crypt-PGA [Trj]?

Win32:Crypt-PGA [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment