Malware

MSIL/Kryptik.KXZ removal guide

Malware Removal

The MSIL/Kryptik.KXZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.KXZ virus can do?

  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/Kryptik.KXZ?


File Info:

name: 7DE893E935D68A1AEF82.mlw
path: /opt/CAPEv2/storage/binaries/00d100854eeca839bb80579bd5d56b415d2f77381c9d566ba8271ec3905fd0c3
crc32: 3E45D970
md5: 7de893e935d68a1aef825cc646321104
sha1: 69db2bde79e83a813508ec20c3300780eca6293e
sha256: 00d100854eeca839bb80579bd5d56b415d2f77381c9d566ba8271ec3905fd0c3
sha512: 142f4e75d524efb3fa582805b5b2c6d4b86f00750e2288a01eb81f50e5a00fbb0ee41029f98f536a61bc4f30973fb5fac80729ee5866d42d680ba8a776851f67
ssdeep: 6144:aCZsTU4DZjUJ4XGkfMlN++hWvAZGbgjljren3NzDQuUgk/mUXwyDF/lPXG5P3Ms2:aCHwUGPfM861sUvl+ktDw6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109A44B1153737585CB20D8B19096D2FD01609FE67E535BE2A0BCFB2906BC25ACD0BBDA
sha3_384: 04a9efebeeddf0347dc231014759b4e5f0ebc85b57190a181a31db248a9f0158ed0f9911c258c633f47c235765285864
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-06-21 22:38:20

Version Info:

Translation: 0x0000 0x04b0
Comments: RPX 1.3.4400.61
FileDescription:
FileVersion: 0.0.0.0
InternalName: Server.exe
LegalCopyright:
OriginalFilename: Server.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/Kryptik.KXZ also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Reconyc.4!c
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
ClamAVWin.Packed.Hpbladabi-6860330-0
FireEyeGeneric.mg.7de893e935d68a1a
McAfeeBackDoor-FAXR!7DE893E935D6
CylanceUnsafe
ZillyaTrojan.Reconyc.Win32.11305
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00528cb81 )
K7GWTrojan ( 00528cb81 )
Cybereasonmalicious.935d68
BitDefenderThetaGen:NN.ZemsilF.34592.Cm0@aytT8de
CyrenW32/MSIL_Confuser.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.KXZ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Reconyc.elrl
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.Reconyc.dthhjc
AvastWin32:Malware-gen
TencentWin32.Trojan.Reconyc.Amwm
Ad-AwareGen:Heur.MSIL.Bladabindi.1
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
DrWebTrojan.DownLoader10.45391
VIPREGen:Heur.MSIL.Bladabindi.1
TrendMicroTSPY_HPCUBESTLR.SM
McAfee-GW-EditionBackDoor-FAXR!7DE893E935D6
Trapminemalicious.high.ml.score
SophosMal/MSIL-PX
IkarusTrojan.MSIL.Inject
GDataGen:Heur.MSIL.Bladabindi.1
JiangminTrojan.Reconyc.azo
AviraHEUR/AGEN.1227310
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.38BB
MicrosoftBackdoor:MSIL/Bladabindi
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R150506
MalwarebytesTrojan.Agent.RP
TrendMicro-HouseCallTSPY_HPCUBESTLR.SM
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:uBc0Fzk40xAAeH3iBTOmCw)
YandexTrojan.Reconyc!MpsYOjJzJS0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injecto.58E1!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MSIL/Kryptik.KXZ?

MSIL/Kryptik.KXZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment