Malware

How to remove “MSIL/Kryptik.AITA”?

Malware Removal

The MSIL/Kryptik.AITA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AITA virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine MSIL/Kryptik.AITA?


File Info:

name: A720E1436388EC5B8A87.mlw
path: /opt/CAPEv2/storage/binaries/f1bd1cf3807876c185cce898d7733b73d52b6337c3caf8d6f6ba0f1ecdbb72cc
crc32: 3B89B4DE
md5: a720e1436388ec5b8a87ea25b66fe6c8
sha1: 24309c776c2e4a349bd73e1bce2a2203ef00de24
sha256: f1bd1cf3807876c185cce898d7733b73d52b6337c3caf8d6f6ba0f1ecdbb72cc
sha512: f4fc93e248d763874a9128e908b6b9c273ff8b7f1ab0564912f19633dbf85368c487777397ffd9851e70449753be224e25af951df42d1864601138204859bbe6
ssdeep: 12288:V8Paty5w0F1ttBTLpJcuwiHjHfsyJbUT8KD9BY:KPatmw0F1tDVDsyRwPBY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9E4BF639FDE6FA2F17CC8789271386843FDED6A0062D199EDFA60E4C7E1B0017A1552
sha3_384: eaa61bdc11327ebcbc453e3d77b8146e32ade00a1c060102272d8e3d00603e98a3e55c4f5608713937b27d84d10f1364
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-03-04 22:31:22

Version Info:

Translation: 0x0000 0x04b0
Comments: 634:;=9C<?AE<:H67D=J
CompanyName: <634:J=?E;G
FileDescription: JH5?=?G>D694H88
FileVersion: 9.14.19.23
InternalName: escalation.exe
LegalCopyright: Copyright © 2018 <634:J=?E;G
OriginalFilename: escalation.exe
ProductName: JH5?=?G>D694H88
ProductVersion: 9.14.19.23
Assembly Version: 1.0.0.0

MSIL/Kryptik.AITA also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.67455202
FireEyeGeneric.mg.a720e1436388ec5b
McAfeeRDN/Generic.hbg
MalwarebytesCrypt.Trojan.MSIL.DDS
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/Kryptik.c862f35c
K7GWTrojan ( 005a4d951 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.36250.Pq0@aGUe9yg
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AITA
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Shelm.gen
BitDefenderTrojan.GenericKD.67455202
AvastWin32:Trojan-gen
TencentMsil.Trojan.Shelm.Jcnw
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1306853
VIPRETrojan.GenericKD.67455202
TrendMicroBackdoor.Win32.SWRORT.YXDFKZ
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
EmsisoftTrojan.GenericKD.67455202 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1306853
MAXmalware (ai score=89)
Antiy-AVLTrojan/MSIL.Kryptik
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Generic.D40548E2
ZoneAlarmHEUR:Trojan.MSIL.Shelm.gen
GDataMSIL.Backdoor.Rozena.GC1IM7
GoogleDetected
Acronissuspicious
ALYacTrojan.GenericKD.67455202
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallBackdoor.Win32.SWRORT.YXDFKZ
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:YgdIaMcxVb6uPljZKtjOmQ)
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.AITA!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.76c2e4
DeepInstinctMALICIOUS

How to remove MSIL/Kryptik.AITA?

MSIL/Kryptik.AITA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment