Malware

What is “MSIL/Kryptik.INN”?

Malware Removal

The MSIL/Kryptik.INN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.INN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.

Related domains:

ocsp.verisign.com
crl.verisign.com
csc3-2009-2-crl.verisign.com

How to determine MSIL/Kryptik.INN?


File Info:

crc32: 563C3A3F
md5: dbe123fed28f1cceb03e3d77f59dafea
name: DBE123FED28F1CCEB03E3D77F59DAFEA.mlw
sha1: e8c0bec8d23898f0f5060237296e798bfcceb69d
sha256: 9a4aae016a70c4272614c76a28714aa1a4a915611ad76060a654d7c2713663f4
sha512: 933710a95c0c3eb67771dd19821d668d541e33817a8c24630db03bb1ba056251781870ff89259d70f97b49d92c5ae6765315f3dc62e34f19e2293a833e88bc31
ssdeep: 24576:aczFj91bQF9dQvUFZjtm4HFOgoqspffpb1oQ57UI22YIV4cFrxj1CcjA:acA9dQvUbjEkFJo/f1CQ5Aer3xCoA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Kryptik.INN also known as:

K7AntiVirusTrojan ( 00507e501 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader17.15248
CynetMalicious (score: 100)
CAT-QuickHealTrojan.BlockFC.S15903951
ALYacGen:Variant.MSIL.Mensa.16
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.37539
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.71d7a153
K7GWTrojan ( 00507e501 )
Cybereasonmalicious.ed28f1
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.INN
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Barys-9884759-0
KasperskyTrojan-Ransom.Win32.Blocker.jynm
BitDefenderGen:Variant.MSIL.Mensa.16
NANO-AntivirusTrojan.Win32.Blocker.engmae
MicroWorld-eScanGen:Variant.MSIL.Mensa.16
TencentMalware.Win32.Gencirc.10bbedb1
Ad-AwareGen:Variant.MSIL.Mensa.16
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34142.KnX@ayn2SAki
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.dbe123fed28f1cce
EmsisoftGen:Variant.MSIL.Mensa.16 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.gqa
AviraHEUR/AGEN.1100384
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASMalwS.1F275C2
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitTrojan.MSIL.Mensa.16
GDataGen:Variant.MSIL.Mensa.16
McAfeeArtemis!DBE123FED28F
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesMalware.AI.3145255586
PandaTrj/GdSda.A
YandexTrojan.Kryptik!+I5mavrprs0
IkarusTrojan.Msil
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.9EF98!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.INN?

MSIL/Kryptik.INN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment