Malware

Should I remove “MSIL.Krypt.41 (B)”?

Malware Removal

The MSIL.Krypt.41 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL.Krypt.41 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (13 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Forces a created process to be the child of an unrelated process
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed analysis tools by registry key
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • The sample wrote data to the system hosts file.
  • Generates some ICMP traffic
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
live.goatgame.live
superstationcity.com
google.vrthcobj.com
ip-api.com
a.upstloans.net
apps.identrust.com
most-fast-link-download.com
crl.identrust.com
b.upstloans.net
connectini.net
privateinvestig8tor.com
iplogger.org
pcandtool.com
choechal.pw
sebeka.info
vexacion.com
cache.uutww77.com
www.profitabletrustednetwork.com
www.directdexchange.com
a.goatagame.com
b.goatfgame.com
x1.c.lencr.org
r3.o.lencr.org
www.bing.com

How to determine MSIL.Krypt.41 (B)?


File Info:

crc32: 0E8B711B
md5: 53186ce79e6468105c773438acbe87f1
name: 53186CE79E6468105C773438ACBE87F1.mlw
sha1: de01fcb76fbabf23a120cee47467b0256704e37a
sha256: 9dbdfabbc99542e1c94b7a29eaf437b7fa4c898c4add1a677b126257ae54f94e
sha512: b711bb7536ed70391db73ccf54ea5f0bb841aa9f0e2c5e97a693cbf3a68caac9511260d4f8acfbb6a86cdae89b4e958cb465c4b440bb62df30cb67806357e7a6
ssdeep: 49152:SunqyEbov0BhJ/0xMW5InyH/tp/pmBCXjn98XEEibJcXDNX:SKqycMnpfzh/n9IiA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MSIL.Krypt.41 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057c9911 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDropNET.43
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.37350686
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0057c9911 )
Cybereasonmalicious.79e646
CyrenW32/Trojan.RONE-2789
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Qshell-9875653-0
KasperskyTrojan-Banker.Win32.Passteal.mu
BitDefenderGen:Variant.MSIL.Krypt.41
NANO-AntivirusTrojan.Win32.Dwn.ixvygg
MicroWorld-eScanGen:Variant.MSIL.Krypt.41
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZemsilCO.34058.pm0@aKxc86d
TrendMicroTROJ_GEN.R002C0DH121
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.53186ce79e646810
EmsisoftGen:Variant.MSIL.Krypt.41 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Banker.Passteal.df
WebrootW32.Malware.Gen
AviraTR/Kryptik.xlrkr
eGambitUnsafe.AI_Score_95%
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:MSIL/Mokes.B!MTB
GridinsoftMalware.Win32.MigratedCloud.cc
GDataWin32.Trojan.Ilgergop.02BTRQ
AhnLab-V3Trojan/Win.Mokes.C4576205
McAfeeGenericRXOO-YN!6AABDF33AFCB
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.SmokeLoader
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DH121
RisingTrojan.Generic@ML.94 (RDMK:CjIsLYSJgP/X2j3yWN1pEA)
YandexTrojan.GenKryptik!zZp2wjZwbXI
IkarusTrojan.MSIL.Krypt
FortinetMSIL/GenKryptik.FFMZ!tr
AVGWin32:DropperX-gen [Drp]
Qihoo-360HEUR/QVM41.1.125B.Malware.Gen

How to remove MSIL.Krypt.41 (B)?

MSIL.Krypt.41 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment