Malware

MSIL/Kryptik.AGHA removal guide

Malware Removal

The MSIL/Kryptik.AGHA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AGHA virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.AGHA?


File Info:

name: AA3CF7DE7843162C96BB.mlw
path: /opt/CAPEv2/storage/binaries/251c6f0553911b75239d27a9b34b57921a29999073fdb583507ec78705f25bde
crc32: BB9127F6
md5: aa3cf7de7843162c96bba45d391e5f18
sha1: c242b93901a6cd875a03da135fbfa97eba3387ac
sha256: 251c6f0553911b75239d27a9b34b57921a29999073fdb583507ec78705f25bde
sha512: ebd8e95453ef3833dbd814ba516f61da6280f772aa75dccfabb3d49fb12f1436022ad52cabce6f0cdb382cd8b2dbd50ab0c653a2a666e39458ba1fb29805ba6e
ssdeep: 24576:e3Z58ckSgC0san2NvACSYJW1wW+0NewFLzqsipIdUz8XT:eJ585i0sHhmb+XMLldQI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B25121C82A64B19F9BD0B7452F0920243727B096833D31F4DD1F9F56EEA766861BF0A
sha3_384: 5c451037012941548f9f35b2cebae05d31432afde2bf2dcb20d9c4cb52fdfd5d68f13f1e62386fdaef1c6d0737eb1839
ep_bytes: ff250020400000000000010000000200
timestamp: 2022-08-31 03:51:14

Version Info:

Translation: 0x0000 0x04b0
Comments: Trending Machine
CompanyName: Susie's Casuals
FileDescription: CAN-SAT
FileVersion: 5.0.0.0
InternalName: oLCB.exe
LegalCopyright: Copyright © Susie's Casuals 2014
LegalTrademarks: Susie's
OriginalFilename: oLCB.exe
ProductName: CAN-SAT
ProductVersion: 5.0.0.0
Assembly Version: 5.0.0.0

MSIL/Kryptik.AGHA also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Maria.3
MicroWorld-eScanTrojan.GenericKD.61632406
FireEyeTrojan.GenericKD.61632479
McAfeeArtemis!AA3CF7DE7843
CylanceUnsafe
SangforInfostealer.Win32.Agent.Vwdi
K7AntiVirusTrojan ( 0059794c1 )
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 0059794c1 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/MSIL_Kryptik.HYO.gen!Eldorado
SymantecScr.Malcode!gdn34
ESET-NOD32a variant of MSIL/Kryptik.AGHA
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.61632479
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-Spy.Noon.Htgl
Ad-AwareTrojan.GenericKD.61632479
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Backdoor.Remcos.JSANDZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Injection.C5230348
VBA32OScope.Trojan.MSIL.Remcos.gen
MAXmalware (ai score=87)
MalwarebytesMachineLearning/Anomalous.97%
TrendMicro-HouseCallTROJ_GEN.R002H0CHV22
RisingSpyware.Noon!8.E7C9 (CLOUD)
IkarusTrojan-Spy.BluStealer
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:PWSX-gen [Trj]

How to remove MSIL/Kryptik.AGHA?

MSIL/Kryptik.AGHA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment