Malware

What is “MSIL/Kryptik.PWP”?

Malware Removal

The MSIL/Kryptik.PWP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.PWP virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Kryptik.PWP?


File Info:

crc32: A93C24FF
md5: f821a3c88c3cae1cbe166bdf71609596
name: F821A3C88C3CAE1CBE166BDF71609596.mlw
sha1: 4977ef8c725a48840fb93a72715e3bb95dbb1aa2
sha256: 568099b426c76312ef0617f1aefb9890222bc3c8a250934e137c91cf31d3438c
sha512: 8032348939883828605328799dedc4a00e77e5af23e14feaea22390572cf0fe36baafb1bfa2ae1d28c56d3682c93f4d5fe842b141c0ef1ec9e8e60eecd66478f
ssdeep: 6144:pWYMzkRXvNQUoZBR5bR0zEvI5BylYKR+J2gUv9B3ujt1gksq:pJMIRfqtZL7YECvYn9B3uj7g
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2012 Larsony Dop Industries Inc
Assembly Version: 0.0.0.0
InternalName: aassa.exe
FileVersion: 6.9.20.1
CompanyName: Larsony Dop Industries Inc
Comments: osagladutokekwopizabosiv
ProductName: Larson Dop Consulting
ProductVersion: 6.9.20.1
FileDescription: Larson Dop Consulting
OriginalFilename: aassa.exe

MSIL/Kryptik.PWP also known as:

K7AntiVirusTrojan ( 00540f7f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.1.Gen
CylanceUnsafe
ZillyaAdware.Blocker.Win32.3
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.4e8040c0
K7GWTrojan ( 00540f7f1 )
Cybereasonmalicious.88c3ca
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.PWP
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderTrojan.MSIL.Basic.1.Gen
ViRobotTrojan.Win32.S.Ransom.449024
MicroWorld-eScanTrojan.MSIL.Basic.1.Gen
TencentMsil.Trojan.Blocker.Ebzt
Ad-AwareTrojan.MSIL.Basic.1.Gen
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34758.Bm0@aKfOMki
TrendMicroTrojanSpy.MSIL.REMCOS.SMK
McAfee-GW-EditionTrojan-FQGG!F821A3C88C3C
FireEyeGeneric.mg.f821a3c88c3cae1c
EmsisoftTrojan.MSIL.Basic.1.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1129514
MicrosoftTrojan:Win32/Tiggre!rfn
AegisLabTrojan.MSIL.Blocker.4!c
GDataTrojan.MSIL.Basic.1.Gen
AhnLab-V3Trojan/Win32.Blocker.C2766844
McAfeeTrojan-FQGG!F821A3C88C3C
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.PasswordStealer.MSIL
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.MSIL.REMCOS.SMK
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.PVO!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.PWP?

MSIL/Kryptik.PWP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment