Malware

Should I remove “MSIL/GenKryptik.CIKI”?

Malware Removal

The MSIL/GenKryptik.CIKI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.CIKI virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Network activity detected but not expressed in API logs

How to determine MSIL/GenKryptik.CIKI?


File Info:

name: 24810F5DCFF56357B37B.mlw
path: /opt/CAPEv2/storage/binaries/22ee9cf951f8f809293f8ff92ffb874a37e6042d936665932b24eddd5ff4b3f1
crc32: 132DE6F9
md5: 24810f5dcff56357b37bbb032f3f0d10
sha1: def716068e2b483d7878df62488e75222f8c421a
sha256: 22ee9cf951f8f809293f8ff92ffb874a37e6042d936665932b24eddd5ff4b3f1
sha512: 836709aa638007f77b7587fa04476697817a980c322e05170c265f4a1dffc096d3849e7cabd675d1d5cac438362bc7c625f401daf38c44088382e218dcb57764
ssdeep: 6144:eBVH6LMyRnkuXgxDcAE21GSZVoXGKHppmExh6HP9k:eBsFR19AZLmWsh6v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A74E1630DCA5618CD5E0BB961720CA842FBFF545ABBF32F898931BACF3B6D45240516
sha3_384: c14589c8b3dab6e87f92e129a12f9aadce40bc3e3be453c6479e3268460de40414bf3f279389cc68b45ff460c136ab06
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-04-10 16:15:23

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: sal.exe
LegalCopyright:
OriginalFilename: sal.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/GenKryptik.CIKI also known as:

LionicTrojan.Win32.Generic.lVvO
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
FireEyeGeneric.mg.24810f5dcff56357
CAT-QuickHealTrojan.GeneFC.S17874303
CylanceUnsafe
SangforTrojan.MSIL.Confuser.mt
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/A-57056955!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.CIKI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Confuser-7052940-0
KasperskyHEUR:Trojan-Dropper.Win32.Generic
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.Tiny.fapwty
AvastMSIL:Ainslot-F [Trj]
TencentWin32.Trojan-dropper.Generic.Hqll
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosMal/Generic-S
ComodoMalware@#3ucszurf8fe5m
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.DownLoader26.36392
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.MSIL.Bladabindi.1
JiangminTrojanDropper.Generic.bgc
AviraTR/Dropper.Gen7
ArcabitTrojan.MSIL.Bladabindi.1
MicrosoftBackdoor:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4151499
McAfeeArtemis!24810F5DCFF5
MAXmalware (ai score=99)
MalwarebytesMalware.AI.1697544678
YandexTrojan.DL.Tiny!Gb2E6yR0dMw
IkarusTrojan-Spy.Agent
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Generic.AP.137131!tr
BitDefenderThetaGen:NN.ZemsilF.34294.um0@ailjR5l
AVGMSIL:Ainslot-F [Trj]
Cybereasonmalicious.dcff56
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/GenKryptik.CIKI?

MSIL/GenKryptik.CIKI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment