Malware

MSIL/Kryptik.LZG malicious file

Malware Removal

The MSIL/Kryptik.LZG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.LZG virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.LZG?


File Info:

name: 2CD5F5ED21B3A9F42684.mlw
path: /opt/CAPEv2/storage/binaries/47f1b4d3f118a373ff5fb50ef90b3cb2b7fe4f6f8fc88d7af815415466928d81
crc32: 39190D6D
md5: 2cd5f5ed21b3a9f42684cd2dcf28365c
sha1: a0b4acc0799459a84b0c85c3e03dc313ae393ec7
sha256: 47f1b4d3f118a373ff5fb50ef90b3cb2b7fe4f6f8fc88d7af815415466928d81
sha512: 6271b4e8fd5669d9ac928c845e407dbb6d8ca8e2640653ad1bc5ceef495e8286f665f567b0eb514c912dc7f7e16f463826a88cc75255b30ce5c71ec40621f12c
ssdeep: 1536:t3eJG53G73mxdvdheu8KpcZXZvpHwfB8tvCbLb2EorD+S8baaLFr:t32GhNv3ppcZVpQnXyvD+S8baE9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167B36A1376D4838BEABD1BB529A2630012F6E91E5136E70C2D44259D4CFA7C2DB927E3
sha3_384: a00647212cfd8c4f8e15195a881b51a9a67380a5e19129aa61c9ecfcbcaf64a1b8141602a24ddcd6ac823fd42fbfa23e
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-01-10 14:03:57

Version Info:

Translation: 0x0000 0x04b0
FileDescription: dwmv
FileVersion: 1.0.0.0
InternalName: dwmv.exe
LegalCopyright: Copyright © 2018
OriginalFilename: dwmv.exe
ProductName: dwmv
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.LZG also known as:

LionicTrojan.MSIL.Zapchast.4!c
MicroWorld-eScanTrojan.GenericKD.12741991
FireEyeGeneric.mg.2cd5f5ed21b3a9f4
ALYacTrojan.GenericKD.12741991
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1980558
SangforTrojan.MSIL.Zapchast.akiqw
K7AntiVirusTrojan ( 00520dde1 )
AlibabaTrojan:MSIL/Zapchast.6450e84f
K7GWTrojan ( 00520dde1 )
Cybereasonmalicious.d21b3a
BitDefenderThetaGen:NN.ZemsilF.34084.gq0@aGOUSuj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.LZG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Generic-9865070-0
KasperskyTrojan.MSIL.Zapchast.akiqw
BitDefenderTrojan.GenericKD.12741991
NANO-AntivirusTrojan.Win32.Drop.dkkfyt
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.12741991
EmsisoftTrojan.GenericKD.12741991 (B)
ComodoMalware@#2qywnst4wgzey
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.12741991
JiangminTrojan.MSIL.acdsb
AviraHEUR/AGEN.1137703
Antiy-AVLTrojan/Generic.ASMalwS.23F69D6
MicrosoftTrojan:MSIL/Bladabindi.DP!MTB
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C4208285
McAfeeArtemis!2CD5F5ED21B3
MAXmalware (ai score=82)
VBA32Trojan.MSIL.Zapchast
TencentMsil.Trojan.Zapchast.Hvjp
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.GVM!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/Kryptik.LZG?

MSIL/Kryptik.LZG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment