Malware

About “MSIL/Kryptik.AFVR” infection

Malware Removal

The MSIL/Kryptik.AFVR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AFVR virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.AFVR?


File Info:

name: 1BCC9F14C7089392CAE5.mlw
path: /opt/CAPEv2/storage/binaries/fd1191fe87873ed3bd7e924bcf902ed69ccc623839bc8213890bcaf156424bd4
crc32: E9D59CD7
md5: 1bcc9f14c7089392cae533ffe61643d1
sha1: e8de0a5ca7e976c2c7f5ecc067900e1055ebf61c
sha256: fd1191fe87873ed3bd7e924bcf902ed69ccc623839bc8213890bcaf156424bd4
sha512: 44b1a16795b1ee8cbdb79b2e63699c08c8f8f51ff6beb19914cea8ea7c1c90d9efe29f7ddbcd365609e31d7997fcaddd0c1a35f43b39acbc496988d7f475c3f3
ssdeep: 12288:i31hlnYLiVCKdLN6Q+kwRPVGTw81pGF6cZMqPSqJO0r8GQ5Xt4BrWcEX/xqsx8:mNfbdLw13tVGzG6cJJO0r25tJHXJDx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0D42379A7BDE770C2778E34E496825CD3F5FE67A121E53B08203E5E086236A19532D3
sha3_384: 41a69b9c144bf46358d0a57e924e22484ee8a08010d3c5b85dfc2e041dd2ead8e00abfd059991ff369053c6e9f7f1dfa
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-24 13:50:10

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: BMap.NET
FileVersion: 1.0.0.0
InternalName: Rea.exe
LegalCopyright: Copyright © 2015
LegalTrademarks:
OriginalFilename: Rea.exe
ProductName: BMap.NET
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.AFVR also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.44349
MicroWorld-eScanGen:Trojan.Olock.1
FireEyeGeneric.mg.1bcc9f14c7089392
McAfeeArtemis!1BCC9F14C708
AlibabaTrojan:Win32/Kryptik.ali2000016
BitDefenderThetaGen:NN.ZemsilF.34806.Mm0@aCI6Vge
CyrenW32/MSIL_Agent.DPL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AFVR
TrendMicro-HouseCallTROJ_GEN.R06CH07GO22
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderGen:Trojan.Olock.1
AvastRATX-gen [Trj]
Ad-AwareGen:Trojan.Olock.1
EmsisoftGen:Trojan.Olock.1 (B)
VIPREGen:Trojan.Olock.1
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminemalicious.moderate.ml.score
IkarusTrojan.MSIL.Inject
GDataGen:Trojan.Olock.1
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Olock.C5213738
ALYacGen:Trojan.Olock.1
MalwarebytesMalware.AI.2768692064
APEXMalicious
RisingTrojan.Generic/MSIL@AI.91 (RDM.MSIL:12X0WQBZy3AgG+ZzaXpkeg)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Variadic.A!tr
AVGRATX-gen [Trj]
Cybereasonmalicious.ca7e97

How to remove MSIL/Kryptik.AFVR?

MSIL/Kryptik.AFVR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment