Malware

MSIL/Kryptik.AGRP removal

Malware Removal

The MSIL/Kryptik.AGRP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AGRP virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Kryptik.AGRP?


File Info:

name: FD0483D583BF1BAEF8C5.mlw
path: /opt/CAPEv2/storage/binaries/c07324559c7e9e3d221168fbcb9c3fc0ba7ee678bdf459299d4016c15d687171
crc32: 00C5C337
md5: fd0483d583bf1baef8c59386e4832f87
sha1: 4f3163d789b9300fcc72cf6ad689d425f31cfda0
sha256: c07324559c7e9e3d221168fbcb9c3fc0ba7ee678bdf459299d4016c15d687171
sha512: ef18e241babd2f799b063cf3bee542682bad65411a2c50e8f0074ca74a7b8b37c27714689a112958238169ae21a8742f2ec0c99e513d1cb6092804551eb36d48
ssdeep: 24576:xnMeR2aXP8OhY3th5CS9bXQSmagHc+Ingh4:JWSPpsthRbNgbG64
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E25CF3A26D2CA0AC1062634CDD3D3F05FE85E91A2B2C70B5FD9BD2FB5072EB5A45584
sha3_384: 3e9c39d273d70f6ee719e548b2972df4c4cf4b0b3bcb6f5d3759a0d1ef5260034071422702bb8af843419c907a603cbb
ep_bytes: ff250020400000000000000000000000
timestamp: 2040-09-26 18:26:57

Version Info:

Translation: 0x0000 0x04b0
Comments: Cutter
CompanyName: The Pink Pig Tavern
FileDescription: Cutter
FileVersion: 1.5.0.0
InternalName: adi.exe
LegalCopyright: The Pink Pig Tavern 22
LegalTrademarks:
OriginalFilename: adi.exe
ProductName: Cutter
ProductVersion: 1.5.0.0
Assembly Version: 1.1.0.0

MSIL/Kryptik.AGRP also known as:

BkavW32.AIDetectMalware.CS
MicroWorld-eScanGen:Variant.Ransom.Loki.124
FireEyeGeneric.mg.fd0483d583bf1bae
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
SkyhighRDN/Generic PWS.y
ALYacGen:Variant.Ransom.Loki.124
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005992f01 )
K7GWTrojan ( 005992f01 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn34
ESET-NOD32a variant of MSIL/Kryptik.AGRP
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
SophosTroj/Krypt-RN
F-SecureHeuristic.HEUR/AGEN.1323977
DrWebTrojan.PWS.Siggen3.23031
VIPREGen:Variant.Ransom.Loki.124
EmsisoftGen:Variant.Ransom.Loki.124 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.ehyh
AviraHEUR/AGEN.1323977
MAXmalware (ai score=80)
Antiy-AVLTrojan/MSIL.Kryptik
ArcabitTrojan.Ransom.Loki.124
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R525595
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
IkarusTrojan-Spy.FormBook
FortinetMSIL/Kryptik.AESA!tr

How to remove MSIL/Kryptik.AGRP?

MSIL/Kryptik.AGRP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment