Malware

MSIL/Kryptik.LEE removal guide

Malware Removal

The MSIL/Kryptik.LEE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.LEE virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates a copy of itself

How to determine MSIL/Kryptik.LEE?


File Info:

crc32: 5F142204
md5: ed39019e58f1e01302c13b1bc5f441d0
name: ED39019E58F1E01302C13B1BC5F441D0.mlw
sha1: 6394983c5d85ca62896b5fbd7c2c923f534f4201
sha256: 215ba371d36efa400acf320c92036ac7419f4020ad7c3636c75a4e4a5124cfc6
sha512: 01e0c0547b603ee42a79a67ac6b0adfb0ff1cd6d5bf345074496a4d16ae89d16d6f67edfd96b644ec463d0b2f5bed2880d03c5f9654ba3ace41e1170162fa2e6
ssdeep: 24576:b5M4dMllYT86lGj8+DqvW+fEMes1ZkreeMORGp0W62abyuTyKU5ylQYsmQ1h:bK4aQT86Aj8+DF+cg+rY9KUsXsm0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Inv#467 565756.com
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Inv#467 565756.com

MSIL/Kryptik.LEE also known as:

K7AntiVirusTrojan ( 005190e41 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Wirenet.351
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.6.Gen
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:MSIL/Kryptik.5dd1097f
K7GWTrojan ( 005190e41 )
Cybereasonmalicious.e58f1e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.LEE
APEXMalicious
AvastWin32:Malware-gen
ClamAVBC.Win.Packed.ConfuserEx-6428556-1
KasperskyHEUR:Trojan-Spy.Win32.Generic
BitDefenderTrojan.MSIL.Basic.6.Gen
NANO-AntivirusTrojan.Win32.Wirenet.fkicqe
MicroWorld-eScanTrojan.MSIL.Basic.6.Gen
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.MSIL.Basic.6.Gen
SophosML/PE-A + Mal/Kryptik-AS
ComodoTrojWare.MSIL.Golroted.EJU@7duncy
BitDefenderThetaGen:NN.ZemsilF.34294.nn0@aabEQpg
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.ed39019e58f1e013
EmsisoftTrojan.MSIL.Basic.6.Gen (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1122372
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.296AC49
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.MSIL.Basic.6.Gen
GDataTrojan.MSIL.Basic.6.Gen
AhnLab-V3Win-Trojan/MSILKrypt03.Exp
Acronissuspicious
McAfeeArtemis!ED39019E58F1
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
YandexTrojan.Kryptik!wyJqCQC/Ki0
IkarusTrojan.MSIL.Krypt
FortinetMSIL/Kryptik.LEE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.LEE?

MSIL/Kryptik.LEE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment