Malware

How to remove “MSIL/Kryptik.AKQF”?

Malware Removal

The MSIL/Kryptik.AKQF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AKQF virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the zgRAT malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine MSIL/Kryptik.AKQF?


File Info:

name: 4E16962266A948B2A7F9.mlw
path: /opt/CAPEv2/storage/binaries/090ffacc31ef8ae49ab2cf586d9d44ff039cc7957ce9de87ae610b5fcea2512e
crc32: 42D1C9BB
md5: 4e16962266a948b2a7f9eff6ea6604c8
sha1: ecfb0e6716005f26c7c94a0f44e483392cbceec9
sha256: 090ffacc31ef8ae49ab2cf586d9d44ff039cc7957ce9de87ae610b5fcea2512e
sha512: c115c3e3982df6c07b72fe14edb6f8cdead4b9161b2f7354ec528ee443e383737e68399265a031d2b3feef03ee8c91f9e8074add0ce06bc12f6696ac52401925
ssdeep: 98304:74rz9zYT7eZjrvUQYmQivOMe7lYfWnwJue/N+wpknbv:8H9zYT74AMle7gpJ//N+/n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C866BE26B768DB23C65E1A33D1C2401463F0C9865753F74B7EC93BA919433AB6D8E1CA
sha3_384: c5b603e30aba8ad3165a70868a06b65257bccc519a7e5b70f3e847da06c6cce3d5c04849b957977956f1ae0aede75b5f
ep_bytes: ff250020400000000000000000000000
timestamp: 2098-11-30 00:31:59

Version Info:

CompanyName: Sakysoft s.r.l.
FileDescription: Burn4Free DVD Burning Software right context menu
FileVersion: 8.9.0.0
InternalName: b4fm.dll
LegalCopyright: Sakysoft s.r.l. 2013-2016
LegalTrademarks: Sakysoft s.r.l. 2013-2016
OriginalFilename: b4fm.dll
ProductName: b4fm.dll
ProductVersion: 8.9.0.0
Comments: www.burn4free.com
Translation: 0x0409 0x04e4

MSIL/Kryptik.AKQF also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Reline.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.71285224
SkyhighArtemis!Trojan
Cylanceunsafe
SangforInfostealer.Msil.Kryptik.V0d2
K7AntiVirusTrojan ( 005b0a671 )
AlibabaTrojan:MSIL/Kryptik.0e43bc63
K7GWTrojan ( 005b0a671 )
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Generic.D43FB9E8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AKQF
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
BitDefenderTrojan.GenericKD.71285224
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Trojan-QQPass.QQRob.Tzfl
EmsisoftTrojan.GenericKD.71285224 (B)
F-SecureTrojan.TR/AD.Nekark.veaqq
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
VaristW32/ABRisk.IMLM-0681
AviraTR/AD.Nekark.veaqq
Antiy-AVLTrojan/MSIL.Kryptik
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan-PSW.MSIL.Reline.gen
GDataTrojan.GenericKD.71285224
GoogleDetected
McAfeeArtemis!4E16962266A9
VBA32Trojan.MSIL.zgRAT.Heur
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0DAK24
RisingStealer.Reline!8.132F4 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AKQF!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.716005
DeepInstinctMALICIOUS

How to remove MSIL/Kryptik.AKQF?

MSIL/Kryptik.AKQF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment