Malware

MSIL/Kryptik.AWI information

Malware Removal

The MSIL/Kryptik.AWI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AWI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Sniffs keystrokes
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine MSIL/Kryptik.AWI?


File Info:

crc32: 9783A272
md5: 9033a59d3fded7fe4710c0de245892ad
name: 9033A59D3FDED7FE4710C0DE245892AD.mlw
sha1: 62d700a67ca0d6b3d182630e70734198b0971d46
sha256: 1902b680a00c8776a19b16047618bf51375d73ca1749b95bf0fbdae9706b47ad
sha512: a52e7bd642fc4057691590cf7b09ed7df3c55249dfa6e43dff8da8da210856c9deb801d9e93086c5fac81f3656b03be21f709172f23ede638efecf798f7c3939
ssdeep: 6144:mkfIlkkyr9qu7q6fbDWw3ubTdbxLxqTgJK4oFApbTZg:vfIlZy97qOb6wSTAL40EbW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Kryptik.AWI also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.51096
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.26848
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.d3fded
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AWI
APEXMalicious
AvastMSIL:GenMalicious-CIZ [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.gozf
BitDefenderTrojan.GenericKDZ.26848
NANO-AntivirusTrojan.Win32.Dwn.dmtnya
MicroWorld-eScanTrojan.GenericKDZ.26848
Ad-AwareTrojan.GenericKDZ.26848
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34670.umX@aOxY8Ui
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.9033a59d3fded7fe
EmsisoftTrojan.GenericKDZ.26848 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.bafuj
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan-Ransom.Win32.Blocker.gozf
GDataTrojan.GenericKDZ.26848
AhnLab-V3Win-Trojan/MDA.19171308.X1376
McAfeeArtemis!9033A59D3FDE
MAXmalware (ai score=87)
VBA32Hoax.Blocker
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Agent!/5S8JV1toYA
FortinetMSIL/Injector.GMX!tr
AVGMSIL:GenMalicious-CIZ [Trj]

How to remove MSIL/Kryptik.AWI?

MSIL/Kryptik.AWI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment