Malware

What is “MSIL/Kryptik.FOP”?

Malware Removal

The MSIL/Kryptik.FOP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.FOP virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.FOP?


File Info:

name: D298454882CAAC154FC9.mlw
path: /opt/CAPEv2/storage/binaries/badaa2312457f3d08ca1f72287989456f9e62d6b417af6fb9b5e39ca1e8c8100
crc32: F6DBD4C9
md5: d298454882caac154fc9217fc7e90499
sha1: 11970a2f8b9d1153fbc7fe925a846bd95e07e96f
sha256: badaa2312457f3d08ca1f72287989456f9e62d6b417af6fb9b5e39ca1e8c8100
sha512: e28a4d7c827b5c816503ddba4fee0bc82b16a0acb2eed9c81b20bb1b043d69b89cd3a1cf2beafb27a2471b6172f707d53e3c90568636b0c65e484e051dfde86f
ssdeep: 1536:irpsoXbrChiH0xLP+VVVVVVVVVVVVVVVVVVVVVVVVVSve:iVtrbH0xLN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11453708235B62271DF81C17B9492C5B5993B6F61173EC97D2CA2FE3A28F1354398AD30
sha3_384: cbe375f5333e974b3ee60f822a42aa79d9fccbe9eeab92ff982979b2bbe437f2ed5f68655c3cbe5eb114c87bdede1dfe
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-20 15:14:28

Version Info:

Translation: 0x0000 0x04b0
Comments: Windows Explorer
CompanyName: Microsoft Corporation
FileDescription: Windows Explorer
FileVersion: 6.1.7800.8900
InternalName: explorer.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: explorer.exe
ProductName: Microsoft Corporation
ProductVersion: 6.1.7800.8900
Assembly Version: 6.1.7800.8900

MSIL/Kryptik.FOP also known as:

LionicTrojan.Win32.Generic.mCko
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Krypt.!cdmip!.2
FireEyeGeneric.mg.d298454882caac15
McAfeeArtemis!D298454882CA
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3647550
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:MSIL/Gorgon.7e4d3202
K7GWTrojan ( 700000121 )
Cybereasonmalicious.882caa
BitDefenderThetaGen:NN.ZemsilF.34084.dm0@a8c4lSn
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.FOP
TrendMicro-HouseCallTROJ_GEN.R002C0WKR21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Gorgon.gen
BitDefenderGen:Heur.MSIL.Krypt.!cdmip!.2
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Gorgon.Wqmq
Ad-AwareGen:Heur.MSIL.Krypt.!cdmip!.2
EmsisoftGen:Heur.MSIL.Krypt.!cdmip!.2 (B)
DrWebTrojan.PackedNET.35
TrendMicroTROJ_GEN.R002C0WKR21
McAfee-GW-EditionArtemis!Trojan
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
GDataGen:Heur.MSIL.Krypt.!cdmip!.2
MaxSecureTrojan.Malware.73911067.susgen
AviraHEUR/AGEN.1104394
Antiy-AVLTrojan/Generic.ASMalwS.34DA5E1
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.RL_Injector.C3488151
VBA32TScope.Trojan.MSIL
ALYacGen:Heur.MSIL.Krypt.!cdmip!.2
MAXmalware (ai score=87)
MalwarebytesTrojan.Crypt
YandexTrojan.Gorgon!3YJsbFEG06Y
IkarusTrojan.MSIL.Crypt
eGambitUnsafe.AI_Score_99%
FortinetMSIL/GenKryptik.ESUKI!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/Kryptik.FOP?

MSIL/Kryptik.FOP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment