Malware

How to remove “MSIL/Kryptik.IFT”?

Malware Removal

The MSIL/Kryptik.IFT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.IFT virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.IFT?


File Info:

name: E7A59609C98502ECC81A.mlw
path: /opt/CAPEv2/storage/binaries/d0585e9d6a6b100e7a09673f99644462a8e8d2d5c42a968ac0c24cb8cc0d1487
crc32: CE1A48AB
md5: e7a59609c98502ecc81a3b3c4f0a6a37
sha1: 7c1b9c9fb456217aad0d1b940c5b1806b216f26d
sha256: d0585e9d6a6b100e7a09673f99644462a8e8d2d5c42a968ac0c24cb8cc0d1487
sha512: e7f5410cdf546d1959b90469be688e2aed1a7823c413e0ac36662bfbf40eba8c26d7420e64968530eb7c7228cb1e3433b068b0754fd4c552cd548041e46bb4a3
ssdeep: 1536:ru5p1QooxeveVWpgxYsaITpNmML33WM8UVO4I5o+jJOzj:iJgxmIyML33WHUovo+A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B553AE44AF8E8B23DA9F997E84E733611630CD570683E70FA4883E55AE703CE52B3556
sha3_384: 850e1101e457bd46962856ceed9fdcdf50c4cdcdf3581e4d172d736e6710087489dd8d5a58d2eb3091b469c3eb372e66
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-03-12 21:44:19

Version Info:

0: [No Data]

MSIL/Kryptik.IFT also known as:

LionicTrojan.Win32.Generic.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.183212
FireEyeGeneric.mg.e7a59609c98502ec
ALYacGen:Variant.Bulz.183212
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0056ea371 )
AlibabaTrojanDropper:Win32/Kryptik.1b1431e2
K7GWTrojan ( 0056ea371 )
Cybereasonmalicious.9c9850
BitDefenderThetaGen:NN.ZemsilF.34212.em0@auGX9Mj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.IFT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.njRAT-7688626-1
KasperskyHEUR:Trojan-Dropper.Win32.Generic
BitDefenderGen:Variant.Bulz.183212
NANO-AntivirusTrojan.Win32.Kryptik.eywynj
AvastWin32:Malware-gen
TencentWin32.Trojan-dropper.Generic.Alsf
Ad-AwareGen:Variant.Bulz.183212
EmsisoftGen:Variant.Bulz.183212 (B)
ComodoMalware@#2iv2ut0b9knvw
DrWebTrojan.DownLoader23.48720
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PII21
McAfee-GW-EditionGenericRXCS-QS!E7A59609C985
SophosML/PE-A + Mal/Kryptik-BI
IkarusTrojan.MSIL.Crypt
GDataGen:Variant.Bulz.183212
JiangminTrojanDropper.Generic.awm
AviraHEUR/AGEN.1236268
ArcabitTrojan.Bulz.D2CBAC
ZoneAlarmHEUR:Trojan-Dropper.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi
AhnLab-V3Win-Trojan/MSILKrypt15.Exp
McAfeeGenericRXCS-QS!E7A59609C985
MAXmalware (ai score=99)
VBA32Trojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0PII21
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:LbCW7gwxHOKxK8Y91KLK+w)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/GenKryptik.EMDJ!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Kryptik.IFT?

MSIL/Kryptik.IFT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment