Malware

MSIL/Kryptik.ADVZ (file analysis)

Malware Removal

The MSIL/Kryptik.ADVZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ADVZ virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine MSIL/Kryptik.ADVZ?


File Info:

name: 5B801802BA95432216A8.mlw
path: /opt/CAPEv2/storage/binaries/27436a1a6690b6ebcf8d6022a95e35f02a57b7132c7b6e5213e9c41167691f11
crc32: 8536C4E4
md5: 5b801802ba95432216a80792d0578af8
sha1: 9569d72260f5b671ca3421f2b3da24277967d50d
sha256: 27436a1a6690b6ebcf8d6022a95e35f02a57b7132c7b6e5213e9c41167691f11
sha512: 20930992e43f1a0178c75eefd45965bd2934444a2841d9af54648a80684daa043a777eab1944a6ad54d707f054f24a432625cb5bda2c51b62e3b31bf78a16070
ssdeep: 3072:g6wsatjMVq1aJyETnw0Zz9EbuJL2/5ipGlXnHyJBA8lPqBohiVVHyH9Km2Y:JvatSq1uyDaL+0JrqfyMzY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144149E023FA88B12DABB9BF05571604C53B6665B2532E2488DF7B3DB15B6B500F52F0B
sha3_384: fd031caed64545408e050d813274532f44b166de9360cd2914133b96c9658a943b13452f7e87954f8db499b50c4eeee8
ep_bytes: ff250020400001020304050607080000
timestamp: 2078-10-28 20:52:55

Version Info:

CompanyName: Murray Hurps Software Pty Ltd
FileDescription: Ad Muncher
FileVersion: 4.94.34121 (Free)
InternalName: Ad Muncher
LegalCopyright: Copyright © Murray Hurps Software Pty Ltd
OriginalFilename: AdMunch.exe
ProductName: Ad Muncher
ProductVersion: 4.94.34121 (Free)
Translation: 0x0409 0x04e4

MSIL/Kryptik.ADVZ also known as:

LionicTrojan.MSIL.Inject.4!c
MicroWorld-eScanTrojan.GenericKD.47787541
FireEyeTrojan.GenericKD.47787541
CAT-QuickHealTrojan.MSIL
McAfeeRDN/Generic.hbg
CylanceUnsafe
K7AntiVirusTrojan ( 0058c5df1 )
AlibabaTrojan:MSIL/AgentTesla.0da9667c
K7GWTrojan ( 0058c5df1 )
Cybereasonmalicious.260f5b
CyrenW32/Trojan.GVC.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ADVZ
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Inject.gen
BitDefenderTrojan.GenericKD.47787541
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan.Inject.Sxye
Ad-AwareTrojan.GenericKD.47787541
EmsisoftTrojan.GenericKD.47787541 (B)
Comodofls.noname@0
DrWebTrojan.Inject4.23506
TrendMicroTROJ_GEN.R011C0WA222
McAfee-GW-EditionRDN/Generic.hbg
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Agent
GDataWin32.Trojan.Agent.IYPRVB
JiangminTrojan.MSIL.alxig
WebrootW32.Trojan.Gen
AviraTR/Kryptik.nmgkb
MAXmalware (ai score=80)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Kryptik.dd!n
MicrosoftTrojan:MSIL/AgentTesla.DVZ!MTB
AhnLab-V3Trojan/Win.AgentTesla.C4895712
ALYacTrojan.GenericKD.47787541
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader.MSIL
TrendMicro-HouseCallTROJ_GEN.R011C0WA222
eGambitPE.Heur.InvalidSig
FortinetMSIL/Kryptik.ADVZ!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Kryptik.ADVZ?

MSIL/Kryptik.ADVZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment