Trojan

Trojan.Agent.MSIL.Krypt removal guide

Malware Removal

The Trojan.Agent.MSIL.Krypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.MSIL.Krypt virus can do?

  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.Agent.MSIL.Krypt?


File Info:

crc32: 06578BB0
md5: a4c0c4b9a041299993f669f45f33542f
name: major.exe
sha1: 42c5a414b44f5698a0170824020499f6aea617bd
sha256: effc2b4841d18a24ac00e9c181845d2618455379bd4f5256d3cd68ccdba7a4dc
sha512: 1e641c3e4b0e5e5225934d87f780352070321a4a735f6b83bf40bec700ff0f2944d23f5cc0a3c01facfefad0af051fcced53c29d24bae10be60989c5b6e82773
ssdeep: 12288:IKj1eiEzTb8SRgm7nJXpIS//RGIqlqRSx0ZBXIt6Bend:IKj1eiWYSRg2SQoIqlqcx0ZBXIt6Ynd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 11.00.9600.16384 (winblue_rtm.130821-1623)
CompanyName: Microsoft Corporation
ProductName: Internet Explorer
ProductVersion: 11.00.9600.16384
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE .MUI
Translation: 0x0409 0x04b0

Trojan.Agent.MSIL.Krypt also known as:

MicroWorld-eScanGen:Variant.Strictor.238880
FireEyeGeneric.mg.a4c0c4b9a0412999
ALYacTrojan.Agent.MSIL.Krypt
CylanceUnsafe
K7AntiVirusTrojan ( 0055eb9b1 )
BitDefenderGen:Variant.Strictor.238880
K7GWTrojan ( 0055eb9b1 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Strictor.238880
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:MSIL/Kryptik.b54a1036
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Kryptik!8.8 (CLOUD)
EmsisoftGen:Variant.Strictor.238880 (B)
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Kryptik.mglel
DrWebTrojan.Nanocore.658
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.jc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
WebrootW32.Malware.Gen
AviraTR/Kryptik.mglel
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Strictor.D3A520
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Malware/Win32.Generic.C2504380
McAfeeRDN/Generic.dx
MalwarebytesTrojan.Crypt.MSIL.Generic
ESET-NOD32a variant of MSIL/Kryptik.UHH
TencentWin32.Trojan.Strictor.Lnns
FortinetMSIL/Kryptik.UGA!tr
Ad-AwareGen:Variant.Strictor.238880
AVGWin32:MdeClass
Cybereasonmalicious.4b44f5
Paloaltogeneric.ml
Qihoo-360HEUR/QVM41.1.EBE5.Malware.Gen

How to remove Trojan.Agent.MSIL.Krypt?

Trojan.Agent.MSIL.Krypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment