Malware

MSIL/Kryptik.ADNL removal instruction

Malware Removal

The MSIL/Kryptik.ADNL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ADNL virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine MSIL/Kryptik.ADNL?


File Info:

name: 47A0270D039F1D040080.mlw
path: /opt/CAPEv2/storage/binaries/bb9af38243969887f4c782393564b74d7bbb89c1cd55e97bee6fe0dcb5bfe57f
crc32: 956B49D3
md5: 47a0270d039f1d040080bee987b93198
sha1: 535801b99195cffb050fd6b1f5520678d34b1d45
sha256: bb9af38243969887f4c782393564b74d7bbb89c1cd55e97bee6fe0dcb5bfe57f
sha512: 606c352f89d148f2e5f956687ed9367c8252c0aee847c0ae24846aea35a07a77e0f6cb4fcff38c09f91baf7d8737b92aff84cdbc1e78ef4b1ce48ac4d7744ee2
ssdeep: 12288:v2PGHOd1AaPAnNGYfiZK44PDu22RXkslajk12xOnTKymtPPCSYNka2NoM0I:oABnMUoYk0Q+tP/0PM0I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14555382123BE6B57E1FE4379541A454C4FF2A802E721CB6B2FFD21C83162FB74652616
sha3_384: 0ffea7604c5178166357b45ee0164b89e3d639e34b5fc21bb2e7e2b277c9b2aa0d124ee1404fe12cc64e5cddb8e3bee3
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-23 21:47:26

Version Info:

Translation: 0x0000 0x04b0
Comments: =;:794FD4G648:=I7@@A2@
CompanyName: I<EB::<?:8;<2<E
FileDescription: 83474:C386E>JIDHEH
FileVersion: 7.10.14.17
InternalName: Lighteum-5.2.1.exe
LegalCopyright: Copyright © 2010 I<EB::<?:8;<2<E
OriginalFilename: Lighteum-5.2.1.exe
ProductName: 83474:C386E>JIDHEH
ProductVersion: 7.10.14.17
Assembly Version: 1.0.0.0

MSIL/Kryptik.ADNL also known as:

DrWebTrojan.Packed2.43139
MicroWorld-eScanTrojan.GenericKD.38103958
FireEyeGeneric.mg.47a0270d039f1d04
McAfeeArtemis!47A0270D039F
CylanceUnsafe
K7AntiVirusTrojan ( 0058ac5b1 )
AlibabaTrojan:MSIL/NanoBot.a6d1b5e0
K7GWTrojan ( 0058ac5b1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ADNL
TrendMicro-HouseCallTROJ_GEN.R03FC0WKQ21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.NanoBot.gen
BitDefenderTrojan.GenericKD.38103958
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKD.38103958
EmsisoftTrojan.GenericKD.38103958 (B)
TrendMicroTROJ_GEN.R03FC0WKQ21
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
GDataTrojan.GenericKD.38103958
AviraTR/Kryptik.zorde
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4788769
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.38103958
MAXmalware (ai score=81)
MalwarebytesTrojan.MZCrypt.MSIL.Generic
APEXMalicious
YandexTrojan.NanoBot!rTQQMBpCUU4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ADNL!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Kryptik.ADNL?

MSIL/Kryptik.ADNL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment