Malware

What is “MSIL/Kryptik.CXI”?

Malware Removal

The MSIL/Kryptik.CXI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.CXI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Detects Sandboxie through the presence of a library
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

Related domains:

micorosoft.myq-see.com

How to determine MSIL/Kryptik.CXI?


File Info:

crc32: E81E2DEF
md5: 502396c1fa55a4a821e6a40a6a981e5c
name: calxc.jpg
sha1: 4229b7d3b00bee00a77d1a19390d8f5ee02daf11
sha256: 455d5a26472d23af051b1db60cfe13bc1d6de0f5ef9a9f3468ec9dd251f8b160
sha512: 7cec1710fbb82249bff7dccd9bf459cd2acd14675be3003def565aef5e6f16441b5f067cad823c827f6f1c3a1fda787b2836415ed5f84916b4fc6eb0a1897742
ssdeep: 3072:8Di4XjayoR+6Ax1IuPo8PV7e0i8jSak6C618:e
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft xa9 2019
Assembly Version: 1.5.1.8
InternalName: ConsoleApp5.exe
FileVersion: 1.4.8.7
CompanyName: Microsoft xa9 2019
LegalTrademarks: MicrosoftCorporation
Comments: MicrosoftCorporation
ProductName: MicrosoftCorporation
ProductVersion: 1.4.8.7
FileDescription: MicrosoftCorporation
OriginalFilename: ConsoleApp5.exe

MSIL/Kryptik.CXI also known as:

MicroWorld-eScanTrojan.GenericKD.33508098
FireEyeGeneric.mg.502396c1fa55a4a8
CAT-QuickHealBackdoor.MSIL
Qihoo-360Generic/Backdoor.633
McAfeeRDN/Generic.glk
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Bladabindi.m!c
SangforMalware
K7AntiVirusTrojan ( 004d462d1 )
BitDefenderTrojan.GenericKD.33508098
K7GWTrojan ( 004d462d1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTrojan.MSIL.MALREP.THCODBO
BitDefenderThetaGen:NN.ZemsilF.34098.lm0@aOu6J6d
CyrenW32/Trojan.XMXO-1546
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojan.MSIL.MALREP.THCODBO
Paloaltogeneric.ml
GDataTrojan.GenericKD.33508098
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
AlibabaBackdoor:MSIL/Kryptik.eea41be1
APEXMalicious
RisingBackdoor.Bladabindi!8.B1F (CLOUD)
Ad-AwareTrojan.GenericKD.33508098
EmsisoftTrojan.GenericKD.33508098 (B)
ComodoMalware@#nwti0g6geaqc
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Kryptik.Win32.1782334
McAfee-GW-EditionRDN/Generic.glk
SophosMal/Mdrop-LE
SentinelOneDFI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FF4B02
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Malware/Win32.RL_Generic.C3511825
ALYacTrojan.GenericKD.33508098
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.CXI
TencentMsil.Backdoor.Bladabindi.Srmx
YandexTrojan.Kryptik!LTDOnu45Hko
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.CXI!tr
AVGWin32:Malware-gen
Cybereasonmalicious.3b00be
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.74622672.susgen

How to remove MSIL/Kryptik.CXI?

MSIL/Kryptik.CXI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment