Malware

MSIL/Kryptik.WTY malicious file

Malware Removal

The MSIL/Kryptik.WTY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.WTY virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.dougamedia.com
www.itnertek.com
www.visioninsurance.review
www.mansiobok.info

How to determine MSIL/Kryptik.WTY?


File Info:

crc32: 29C59008
md5: cd8d396fefb42859406abdbc0462f6b4
name: aguerox.exe
sha1: 2d7be62458c8ba59ea95bd5d522cff54d53c6917
sha256: 77c594f90f4773f5adc37678697258ae1db4f8963adbc85dd2c4d6b00d8a74b1
sha512: 1fcb20e14437e037405c30c9dda89b0d45e264323a336534e2016f8a98cc1fc7dfabf7d457577f8677178fb1997def69806f5646ff972325af1132969fc6d1ff
ssdeep: 12288:J4U+Hg8Tk3nk0jskko0kkTmZjJU+Hg8Tk3nk0jskko0kkTmZjggLxXTKtt9KuvCv:uUB5JUB5gqTKSqlQJXbl
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2007-2020 Box Office Mojo
Assembly Version: 1.2.53.0
InternalName: Afxwo.exe
FileVersion: 1.2.14.2
CompanyName: IMDb
LegalTrademarks: IMDb
Comments: Box Office Mojo
ProductName: Movie DB
ProductVersion: 1.2.14.2
FileDescription: Movie DB
OriginalFilename: Afxwo.exe

MSIL/Kryptik.WTY also known as:

DrWebTrojan.PackedNET.380
MicroWorld-eScanTrojan.GenericKDZ.68586
FireEyeGeneric.mg.cd8d396fefb42859
Qihoo-360Generic/Trojan.PSW.374
MalwarebytesTrojan.MalPack
K7AntiVirusTrojan ( 0056a5461 )
BitDefenderTrojan.GenericKDZ.68586
Cybereasonmalicious.458c8b
ArcabitTrojan.Generic.D10BEA
CyrenW32/MSIL_Agent.BMN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.WTY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKDZ.68586
EmsisoftTrojan.GenericKDZ.68586 (B)
F-SecureTrojan.TR/AD.Swotter.amqej
TrendMicroTROJ_GEN.R002C0DGA20
FortinetMSIL/GenKryptik.ENXE!tr
Trapminemalicious.high.ml.score
F-ProtW32/MSIL_Agent.BMN.gen!Eldorado
AviraTR/AD.Swotter.amqej
MAXmalware (ai score=85)
Endgamemalicious (high confidence)
MicrosoftTrojan:MSIL/AgentTesla.VN!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
CynetMalicious (score: 90)
McAfeeFareit-FWT!CD8D396FEFB4
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGA20
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.AvsArher.bTJEKx
IkarusWin32.Outbreak
GDataWin32.Trojan-Stealer.FormBook.8WPMHD
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Kryptik.WTY?

MSIL/Kryptik.WTY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment