Malware

MSIL/Kryptik.WNI removal guide

Malware Removal

The MSIL/Kryptik.WNI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.WNI virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Kryptik.WNI?


File Info:

crc32: 5B8FB64E
md5: ea2a9551a96d5f6ef23988d210235284
name: EA2A9551A96D5F6EF23988D210235284.mlw
sha1: aa63dc4def37eaa7cbdcccecc0fa290a2e4baa32
sha256: 9e0c6888bb6e17c927b7b52656b067562b7ef4607ca3963c8e13637235432c45
sha512: f08028db66063a6e47cdfce8cf5ffea5b14d724dedfce1ae06eb81b1e30dd4398dc8f6599210531b48ff236ab63ab8d7715321406dbd28a7e2f02e713062c882
ssdeep: 12288:5IklCWRTvi/GcbO67yVOWa96qPXtDdYI8unv1DClLAAtXiaLQO+pczN1d:5jlJ7ieQiuVF0cOlsAliQQFAn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: DpiScaling
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Display Control Panel
OriginalFilename: DPISCALING.EXE
Translation: 0x0409 0x04b0

MSIL/Kryptik.WNI also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.32864
CynetMalicious (score: 99)
ALYacGen:Variant.Barys.2630
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1a96d5
ESET-NOD32a variant of MSIL/Kryptik.WNI
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Backdoor.MSIL.Cybergate.gen
BitDefenderGen:Variant.Barys.2630
MicroWorld-eScanGen:Variant.Barys.2630
Ad-AwareGen:Variant.Barys.2630
SophosML/PE-A
F-SecureTrojan.TR/Crypt.CFI.Gen
BitDefenderThetaGen:NN.ZemsilF.34790.Tu0@a8Gywkpi
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
FireEyeGeneric.mg.ea2a9551a96d5f6e
EmsisoftGen:Variant.Barys.2630 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.dgob
AviraTR/Crypt.CFI.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.3047542
MicrosoftTrojan:Win32/AgentTesla!ml
ArcabitTrojan.Barys.DA46
ZoneAlarmHEUR:Backdoor.MSIL.Cybergate.gen
GDataGen:Variant.Barys.2630
MAXmalware (ai score=83)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
IkarusTrojan-Downloader.MSIL.Small
AVGWin32:DropperX-gen [Drp]
Qihoo-360HEUR/QVM03.0.5DA7.Malware.Gen

How to remove MSIL/Kryptik.WNI?

MSIL/Kryptik.WNI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment