Malware

How to remove “MSIL/GenKryptik.CTPZ”?

Malware Removal

The MSIL/GenKryptik.CTPZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.CTPZ virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Exhibits behavior characteristic of Nanocore RAT
  • Collects information to fingerprint the system

How to determine MSIL/GenKryptik.CTPZ?


File Info:

crc32: 70ACB8C3
md5: 2fa83ff5f6a9139f55dbc63b68fa8484
name: hello_from_vax.exe
sha1: d41da164e85ca532c7b4da8205ae269d9ef4cc15
sha256: 77702374ee731ae86104010401c40f0b450f7249215c97df5e6fe602025a0f92
sha512: f1cd4cd40d62f6f3823be16bed27441b89ac4866d02e02f80bcf89b95db26fe09641c988bd8fb629a8b58311befc69aecdc714056854f782314d74cd83dad123
ssdeep: 3072:c8Z+Ze0Q2W2SwgKApPfdWbqnN5TWoy4Ss+lvebSEhHF7hIB10zZ/ilsNy9jTKHV:cM2cNdWbqvTTt+he2Eh2wZ/UQek5h/n
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright 2017 Google Inc. All rights reserved.
InternalName: chrome_exe
CompanyShortName: Google
FileVersion: 69.0.3497.100
CompanyName: Google Inc.
ProductShortName: Chrome
ProductName: Google Chrome
LastChange: 8920e690dd011895672947112477d10d5c8afb09-refs/branch-heads/3497@#948
ProductVersion: 69.0.3497.100
FileDescription: Google Chrome
OriginalFilename: chrome.exe
Official Build: 1
Translation: 0x0409 0x04b0

MSIL/GenKryptik.CTPZ also known as:

MicroWorld-eScanTrojan.GenericKD.31289495
CAT-QuickHealTrojan.IGENERIC
McAfeeRDN/Generic.dx
CylanceUnsafe
BitDefenderTrojan.GenericKD.31289495
K7GWTrojan ( 0054384b1 )
K7AntiVirusTrojan ( 0054384b1 )
ArcabitTrojan.Generic.D1DD7097
TrendMicroTROJ_GEN.R004C0DJI18
NANO-AntivirusTrojan.Win32.NanoBot.fjhycw
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R004C0DJI18
Paloaltogeneric.ml
GDataTrojan.GenericKD.31289495
KasperskyHEUR:Trojan.MSIL.NanoBot.gen
AegisLabTrojan.MSIL.NanoBot.4!c
RisingTrojan.FakeChrome!1.9C7B (CLOUD)
Ad-AwareTrojan.GenericKD.31289495
EmsisoftTrojan.GenericKD.31289495 (B)
ComodoMalware@#5j1cuv2h6d7j
F-SecureHeuristic.HEUR/AGEN.1036588
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
CyrenW32/Trojan.NTKV-2789
AviraHEUR/AGEN.1036588
MAXmalware (ai score=100)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
Endgamemalicious (high confidence)
ZoneAlarmHEUR:Trojan.MSIL.NanoBot.gen
AhnLab-V3Win-Trojan/FCN.140610
Acronissuspicious
ALYacTrojan.GenericKD.31289495
MalwarebytesTrojan.MalPack.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.CTPZ
TencentMsil.Trojan.Nanobot.Hvjs
YandexTrojan.NanoBot!
SentinelOnestatic engine – malicious
FortinetMSIL/Kryptik.LOA!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.5f6a91
AvastWin32:RATX-gen [Trj]
CrowdStrikemalicious_confidence_100% (D)
Qihoo-360Win32/Trojan.BO.573

How to remove MSIL/GenKryptik.CTPZ?

MSIL/GenKryptik.CTPZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment