Malware

MSIL/Kryptik.NRT removal

Malware Removal

The MSIL/Kryptik.NRT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.NRT virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Kryptik.NRT?


File Info:

name: 60ED854A1957CDD8C5D4.mlw
path: /opt/CAPEv2/storage/binaries/40840d3465b8419c3a2c412a729754949283fbe589fea7d043922e0cc7463759
crc32: 2020A610
md5: 60ed854a1957cdd8c5d431931cbdf9d8
sha1: 4e46001fe09d608da097663e1e6bd7c724c9779f
sha256: 40840d3465b8419c3a2c412a729754949283fbe589fea7d043922e0cc7463759
sha512: 4869dda7890d8de6376d7d492f3abc4a7d3d0b6b2175d64e30ee11c9ad2c001ebcbee5f6de1a2c5caec86fdaec3205b0bd5684b1e88fd26fad35a36ba62d0ee5
ssdeep: 1536:ngfPXGN13DWm9y1lIWIvyc4fK8NOk8BTUCWnNPT2UoKQF6qxjOM6dxzUNcLx:ngfPXGLWN8SPToKor8Rxz/x
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DF31855629C8B63C57D97F8A0A5E03153B45EA37092EB098FC23DDB3DB7F604A1068B
sha3_384: 79392a8799e034130061de7c8c8cf404c0560dc581ac6ed7b538ea4ab2a68125d09bec2ce7c666fce36b56338e39b3d7
ep_bytes: ff2500204000456e747279506f696e74
timestamp: 2067-01-30 01:10:38

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Registry
FileVersion: 1.0.0.0
InternalName: Registry.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Registry.exe
ProductName: Registry
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.NRT also known as:

LionicTrojan.MSIL.Bladabindi.m!c
DrWebTrojan.Siggen15.62655
MicroWorld-eScanIL:Trojan.MSILZilla.7548
FireEyeIL:Trojan.MSILZilla.7548
McAfeeArtemis!60ED854A1957
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 0052e21d1 )
K7AntiVirusTrojan ( 0052e21d1 )
CyrenW32/MSIL_Kryptik.AWE.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.NRT
TrendMicro-HouseCallTROJ_GEN.R011C0WL721
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-6898706-0
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderIL:Trojan.MSILZilla.7548
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Msilzilla.Wpab
Ad-AwareIL:Trojan.MSILZilla.7548
EmsisoftIL:Trojan.MSILZilla.7548 (B)
TrendMicroTROJ_GEN.R011C0WL721
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
GDataIL:Trojan.MSILZilla.7548
AviraTR/Kryptik.nyrgw
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Kryptik.163840.WW
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MSILZilla.C4824041
ALYacIL:Trojan.MSILZilla.7548
MAXmalware (ai score=85)
MalwarebytesBackdoor.Bladabindi
APEXMalicious
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetMSIL/Kryptik.NRT!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Kryptik.NRT?

MSIL/Kryptik.NRT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment