Malware

Win32:Crypt-PGB [Trj] (file analysis)

Malware Removal

The Win32:Crypt-PGB [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Crypt-PGB [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32:Crypt-PGB [Trj]?


File Info:

name: 4F41A5D8322BBFC57262.mlw
path: /opt/CAPEv2/storage/binaries/5250cfcf42881c47fd0bcff9110c53da8e6819f240bcff45669d2e73493adfaf
crc32: C1972018
md5: 4f41a5d8322bbfc572627b3a046db035
sha1: 0b590ca77a4ac2e369f4f84aa13979f2c6966f3d
sha256: 5250cfcf42881c47fd0bcff9110c53da8e6819f240bcff45669d2e73493adfaf
sha512: 84dc9dd45ab782b121a442a47690c5daabbde230ddce621b8074dec48a7167bdfbf02b107d87a2ebb7a15f1e1024897c972e2692da8c688cce503c4125c6cfc6
ssdeep: 1536:YTFLlKwHibXlVMfNhSPDtv43BxsyusK7IHYWYgMLofF:YTFLlKwHiPMjSPDtv4xyyNKUHnYefF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B73E141DDC287ADF4B6203309579D5AAEAB6D7ED8ED04389EE7B0713D722022A3345D
sha3_384: 92424ba02189c6d12bdd5b38dac6272c0aab8b9acbb17104629ed2e904f1cf7064f833456c36f2e2eec926842f18ed97
ep_bytes: be0421400033c983c6928b068bf0c1e6
timestamp: 2013-03-24 18:05:54

Version Info:

0: [No Data]

Win32:Crypt-PGB [Trj] also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.VIZ.7
FireEyeGeneric.mg.4f41a5d8322bbfc5
CAT-QuickHealTrojanPWS.Zbot.Gen
CylanceUnsafe
VIPREGen:Heur.VIZ.7
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f49f1 )
K7GWTrojan ( 0040f49f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Kryptik.h
CyrenW32/FakeAlert.YX.gen!Eldorado
SymantecPacked.Generic.402
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BBHP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VIZ.7
NANO-AntivirusTrojan.Win32.Urausy.digdpo
SUPERAntiSpywareTrojan.Agent/Gen-Undef
AvastWin32:Crypt-PGB [Trj]
TencentWin32.Trojan.Generic.Swhl
Ad-AwareGen:Heur.VIZ.7
ComodoTrojWare.Win32.Kryptik.BAWW@4xecqg
DrWebTrojan.Packed.24465
TrendMicroTROJ_RANSOM.SMKK
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.VIZ.7 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.VIZ.7
AviraTR/Urausy.EB.12
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Urausy.C
GoogleDetected
AhnLab-V3Trojan/Win32.FakeAV.R66222
McAfeeBackDoor-FATM!4F41A5D8322B
MAXmalware (ai score=85)
VBA32Heur.Trojan.Hlux
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_RANSOM.SMKK
RisingBackdoor.Agent!1.6954 (CLASSIC)
YandexTrojan.GenAsa!epKw380izU0
IkarusVirus.Agent
FortinetW32/Kryptik.AXUE!tr
BitDefenderThetaGen:NN.ZexaF.34646.euW@aiLj2Lmi
AVGWin32:Crypt-PGB [Trj]
Cybereasonmalicious.8322bb
PandaTrj/Genetic.gen

How to remove Win32:Crypt-PGB [Trj]?

Win32:Crypt-PGB [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment