Malware

MSIL/Kryptik.RJL removal guide

Malware Removal

The MSIL/Kryptik.RJL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.RJL virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/Kryptik.RJL?


File Info:

name: F213705280E2A5CCC461.mlw
path: /opt/CAPEv2/storage/binaries/640e08a4bef4be728a71f5dbc057714843328b1ef5ee5278df19425b3f72f188
crc32: A2114141
md5: f213705280e2a5ccc461693160cad07d
sha1: aff12d7297fa70b135391f3ff20679238d5c975f
sha256: 640e08a4bef4be728a71f5dbc057714843328b1ef5ee5278df19425b3f72f188
sha512: cfdbab603284935133e67b05643e3beb6ecf29d134ed4dab9cdc3abb59f6f3ee56abb8f8117704102e85609acf72aa7376658b9fe0e929ecc9410b04df0ed5d1
ssdeep: 3072:dugA72i2RHksDIl77ChK12y5tW0s1SDNWaFsNlnujMCJdEUiGiPBVm/VexUPuPuE:YK/GxIW+WtTqjmHPuqiY8lW5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170443A343AFB5019B173FFA69AE8B9A6AE2FB7333707646D204103864713942DD91639
sha3_384: 0b2ebb5bf98f4529f1135945d7a127e0bdeb7e821df60128aabbea110660d56a74c6127209194d2ef1b9174208de0f8c
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-11-15 19:30:30

Version Info:

Translation: 0x0000 0x04b0
Comments: Brwa
CompanyName: Brwa Dlshad
FileDescription: Hidden
FileVersion: 4.23.17.462
InternalName: Client1.exe
LegalCopyright: FUD
OriginalFilename: Client1.exe
ProductName: HiDDen
ProductVersion: 4.23.17.462
Assembly Version: 0.0.0.0

MSIL/Kryptik.RJL also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.SpyGate.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.86
MicroWorld-eScanTrojan.MSIL.Basic.10.Gen
FireEyeGeneric.mg.f213705280e2a5cc
SkyhighGenericRXHK-QF!F213705280E2
McAfeeGenericRXHK-QF!F213705280E2
Cylanceunsafe
VIPRETrojan.MSIL.Basic.10.Gen
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054c1641 )
AlibabaBackdoor:MSIL/SpyGate.ff9a42fb
K7GWTrojan ( 0054c1641 )
Cybereasonmalicious.297fa7
ArcabitTrojan.MSIL.Basic.10.Gen
BitDefenderThetaGen:NN.ZemsilF.36744.qm0@ae5QK5f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.RJL
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Backdoor.MSIL.SpyGate.gen
BitDefenderTrojan.MSIL.Basic.10.Gen
NANO-AntivirusTrojan.Win32.SpyGate.gimryh
AvastWin32:BackdoorX-gen [Trj]
TencentMsil.Backdoor.Spygate.Qgil
EmsisoftTrojan.MSIL.Basic.10.Gen (B)
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Kryptik.Win32.1865379
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Small
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Backdoor]/MSIL.SpyGate
XcitiumMalware@#39fesvija8owi
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Backdoor.MSIL.SpyGate.gen
GDataTrojan.MSIL.Basic.10.Gen
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.C3576920
ALYacTrojan.MSIL.Basic.10.Gen
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:IHm439yg/HM64H+HFxhy6A)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.DFGQ!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Kryptik.RJL?

MSIL/Kryptik.RJL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment