Malware

MSIL/Kryptik.KDG (file analysis)

Malware Removal

The MSIL/Kryptik.KDG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.KDG virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a file
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine MSIL/Kryptik.KDG?


File Info:

crc32: D2C1EC25
md5: 4a5f2f1f3f38fc6e3c9b6a746e1e0857
name: autokliker.exe
sha1: 2d8aaea4b525b475e66679d1b0e498a6c003b72e
sha256: 8c13bccbda4ac9cd36d52a8205e7068834a51989ed55bd152cacca38ca1ec2fc
sha512: 2d79d6832f54615e57cfeff55d7796626df3f7d4674432fd4396286efcb8e51d8f95e12eef5963c7d03935f1b651ee39e75e6465481e4370d84682ef5644e345
ssdeep: 98304:9Xz+qeHoUCmGYvVnsxOqDP3fJNzui29fiJ0c+5HRN73jREMdQsbN72Fnj/mOrTpx:FKqt/mVVnsf3BNChu0cSNDjREUQsctiy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa0
FileDescription: x41fx440x438x43box436ex43dx438exa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0xa0
FileVersion: 1.00
Comments:
CompanyName: xa0
Translation: 0x0409 0x04e4

MSIL/Kryptik.KDG also known as:

MicroWorld-eScanTrojan.GenericKD.12559674
McAfeeArtemis!4A5F2F1F3F38
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.12559674
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f3f38f
TrendMicroTROJ_GEN.R057C0GCT20
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Jorik.KJ
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.12559674
KasperskyHEUR:Trojan.MSIL.Generic
NANO-AntivirusRiskware.Win32.MAgentKill.ejvwcr
Ad-AwareTrojan.GenericKD.12559674
SophosGeneric PUA NM (PUA)
F-SecureHeuristic.HEUR/AGEN.1000541
DrWebTrojan.MulDrop7.25239
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.4a5f2f1f3f38fc6e
EmsisoftTrojan.GenericKD.12559674 (B)
IkarusTrojan.BAT.RA
CyrenW32/Trojan.SW.gen!Eldorado
JiangminTrojanSpy.SpyEyes.myc
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
AviraHEUR/AGEN.1000541
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.BTSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.DBFA53A
ZoneAlarmHEUR:Trojan.MSIL.Generic
MicrosoftTrojan:Win32/Tiggre!rfn
ALYacTrojan.GenericKD.12559674
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.KDG
TrendMicro-HouseCallTROJ_GEN.R057C0GCT20
RisingMalware.Undefined!8.C (CLOUD)
SentinelOneDFI – Suspicious PE
FortinetRiskware/MAgentKill
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Virus.RiskTool.4ef

How to remove MSIL/Kryptik.KDG?

MSIL/Kryptik.KDG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment