Malware

MSIL/Kryptik.EBS removal tips

Malware Removal

The MSIL/Kryptik.EBS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.EBS virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Creates known Njrat/Bladabindi RAT registry keys
  • Binary compilation timestomping detected

How to determine MSIL/Kryptik.EBS?


File Info:

name: 10C66ABCDEF5EB3F32B2.mlw
path: /opt/CAPEv2/storage/binaries/a153036ec08bdc5a8d17695a438d8b6449415320d798a5b05cfd98a9013967c6
crc32: E8FAB5FB
md5: 10c66abcdef5eb3f32b2ce552967e599
sha1: 34590fd9a32cc925b7d68312f1ff0763ab9a808a
sha256: a153036ec08bdc5a8d17695a438d8b6449415320d798a5b05cfd98a9013967c6
sha512: 93b50cc8c9e0ba5856baab6deb099ee6d27b294740ae8f5621b545a355fef3639bd8fbdccbf94b3ec8aaedc318be499581945e19d9198b17fa8f5b1274ff3b90
ssdeep: 1536:ljjFNdntQOzhG4Am+PvtKuvxluzolol869kiqV:ljRNdnWO84Am+PvtKuvOMlF69kiqV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ED73830253F9F7BDD554EBB43989019184E5FB3026E7DF58DCBB4282242A868B352DF2
sha3_384: f020615eac87b54bb1fb98176ab9de93decbe48d8156541c211ebcdc457b97498a5a02e41a6d2fbcb67eaca5ed087faa
ep_bytes: ff250020400000000000000000000000
timestamp: 2043-01-20 05:44:04

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: google
FileVersion: 1.0.0.0
InternalName: google.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: google.exe
ProductName: google
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.EBS also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Bulz.217404
FireEyeGeneric.mg.10c66abcdef5eb3f
ALYacGen:Variant.Bulz.217404
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3302623
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004d5a8f1 )
AlibabaTrojan:MSIL/Kryptik.3f7a64da
K7GWTrojan ( 004d5a8f1 )
Cybereasonmalicious.cdef5e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.EBS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.217404
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Dxna
Ad-AwareGen:Variant.Bulz.217404
EmsisoftGen:Variant.Bulz.217404 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic.cf
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
GDataGen:Variant.Bulz.217404
AviraHEUR/AGEN.1241383
Antiy-AVLTrojan/Generic.ASMalwS.337BDB6
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4526405
McAfeeRDN/Generic.cf
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Bladabindi.MSIL
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL:sy+ZR3Q0kpwQqplmQlbY9Q)
YandexTrojan.Agent!of7ngBnLSfg
SentinelOneStatic AI – Malicious PE
FortinetMSIL/CoinMiner.BHP!tr
BitDefenderThetaGen:NN.ZemsilF.34182.em0@aS@q4Fl
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Kryptik.EBS?

MSIL/Kryptik.EBS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment