Malware

MSIL/Kryptik.AADF removal tips

Malware Removal

The MSIL/Kryptik.AADF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AADF virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

How to determine MSIL/Kryptik.AADF?


File Info:

crc32: 388FD9A8
md5: 8c7fdfe7fc53a9ed5d440aca7a1f70aa
name: 8C7FDFE7FC53A9ED5D440ACA7A1F70AA.mlw
sha1: 3d7f0923614e1173b472b9e7b6ca5e1ccfdb0d84
sha256: 7b4088ae7dcb358f6054c3945ca02e944009dafbfc96267f95bae4049c5eca57
sha512: 5ed1e0c85b1861bd41ba33abef58d9b65279499ca4db5d7d5064fd7dc9012ab04e5ab4dd0ec21a0928db32f5aabbbf2ed3cf07d9c85842da7b8c6ff3af7fe27a
ssdeep: 12288:vapQrC5jt4oQTzDrsaN17W+kkUVAOPoNvPhvhGWOqpxvbC2fd+jJ1Xj0mPlJiJE:v/WVt1QTHrsanS6U8hI8b1+Pj0AiJE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 1.0.0.0
InternalName: ADAsyncWorkItem.exe
FileVersion: 1.0.0.0
CompanyName: Northern Reflections
LegalTrademarks:
Comments: 2006 Mini Cooper
ProductName: Bloc
ProductVersion: 1.0.0.0
FileDescription: Bloc
OriginalFilename: ADAsyncWorkItem.exe

MSIL/Kryptik.AADF also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.3614e1
CyrenW32/MSIL_Kryptik.DQY.gen!Eldorado
SymantecScr.Malcode!gdn30
ESET-NOD32a variant of MSIL/Kryptik.AADF
APEXMalicious
KasperskyVHO:Backdoor.Win32.Remcos.gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34628.4m0@amSMZse
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8c7fdfe7fc53a9ed
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!8C7FDFE7FC53
MalwarebytesMalware.AI.3227348472
IkarusTrojan.Inject
Qihoo-360HEUR/QVM03.0.1899.Malware.Gen

How to remove MSIL/Kryptik.AADF?

MSIL/Kryptik.AADF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment