Malware

MSIL/Kryptik.LBY malicious file

Malware Removal

The MSIL/Kryptik.LBY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.LBY virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/Kryptik.LBY?


File Info:

name: 0A4BFC2DD4CB297D4AA1.mlw
path: /opt/CAPEv2/storage/binaries/c6e4cd3c82decf58eb35386030475592968528573dc4bf20915c0c39c7c5d871
crc32: 743876C6
md5: 0a4bfc2dd4cb297d4aa1735722b42690
sha1: d9f74e78ceebc811cf253fcbac53d36ab74b0e15
sha256: c6e4cd3c82decf58eb35386030475592968528573dc4bf20915c0c39c7c5d871
sha512: aa5a83bd7e471f4999bf92e0c0db3e2c075dcea18b5c9863bcc742226ef701c5263d2aded7720a0faadbf3f382d934c981fac28689dcd4edef67295a4da0c69f
ssdeep: 6144:b+SdR4A3s2kMMnt4ST0Pagib9ofifp64NhAIY4BoTI:ZR5nMntNAigKCm6U4b
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17334CF57A7DFAC4AC57D4236237303E9823ADE021642F73B70E83B96897869B75427C1
sha3_384: ab895cb61373aca075f3074535298718f7db598bbce20c007094541f1a112aee9d54408d27e7dfd43c8e4679c17936b2
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-02-14 01:00:37

Version Info:

Translation: 0x0000 0x04b0
Comments: explorer.exe
CompanyName: explorer.exe
FileDescription: explorer.exe
FileVersion: 0.0.0.0
InternalName: Windows.exe
LegalCopyright: explorer.exe
LegalTrademarks: explorer.exe
OriginalFilename: Windows.exe
ProductName: explorer.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/Kryptik.LBY also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Bladabindi.1
FireEyeGeneric.mg.0a4bfc2dd4cb297d
McAfeeArtemis!0A4BFC2DD4CB
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaTrojan:MSIL/Kryptik.59444bff
Cybereasonmalicious.dd4cb2
BitDefenderThetaGen:NN.ZemsilF.34084.om0@a8eh6sh
SymantecTrojan.Gen
ESET-NOD32a variant of MSIL/Kryptik.LBY
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-6018642-0
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Heur.MSIL.Bladabindi.1
NANO-AntivirusTrojan.Win32.GenericKD.elpysb
AvastWin32:Malware-gen
TencentWin32.Trojan.Generic.Fih
Ad-AwareGen:Heur.MSIL.Bladabindi.1
SophosMal/Generic-S
ComodoMalware@#xi1ch1gd9a60
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
EmsisoftGen:Heur.MSIL.Bladabindi.1 (B)
IkarusTrojan.MSIL.Crypt
GDataGen:Heur.MSIL.Bladabindi.1
JiangminTrojan.Generic.atrmd
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1112945
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASBOL.38BB
KingsoftWin32.Troj.Undef.(kcloud)
APEXMalicious
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Dynamer.C1822773
Acronissuspicious
MalwarebytesTrojan.Agent.Generic
YandexTrojan.Agent!RlGnueo8w8E
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Injecto.58E1!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Kryptik.LBY?

MSIL/Kryptik.LBY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment