Malware

What is “MSIL/Kryptik.XFB”?

Malware Removal

The MSIL/Kryptik.XFB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.XFB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine MSIL/Kryptik.XFB?


File Info:

crc32: 1039D9D1
md5: cddcaaf646b126f8b18026f51d355137
name: upload_file
sha1: d28c464f2f722f7310a790e1a494e3bacd4b0364
sha256: 0d6502ebac7f57de3c41d7077d2c613dc31f7f58bef5deb486ff0364e9ff97fe
sha512: 09579057f193eb6a8db6cba082984d4053c09ee4e03c77ca4e352c296289e563ad3ed153d7ca0569a43a889f46b7f3d3f8df292d665ada2e6f83dd3b6853e81a
ssdeep: 12288:nrEOE+aTafQAG2Z2887mXabDO+FW12JpfYxbtHf:rEOtSafQWsX7WkDNhfYxbt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2005-2020 Piriform Software Ltd
Assembly Version: 5.69.0.0
InternalName: gdZDF.exe
FileVersion: 5.69.0.0
CompanyName: Piriform Software Ltd
LegalTrademarks: piriform-cc
Comments: CCleaner
ProductName: CCleaner
ProductVersion: 5.69.0.0
FileDescription: CCleaner
OriginalFilename: gdZDF.exe

MSIL/Kryptik.XFB also known as:

MicroWorld-eScanTrojan.GenericKD.43573765
FireEyeGeneric.mg.cddcaaf646b126f8
McAfeeRDN/Generic.hbg
K7AntiVirusTrojan ( 0056bb1d1 )
BitDefenderTrojan.GenericKD.43573765
K7GWTrojan ( 0056bb1d1 )
Cybereasonmalicious.f2f722
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.43573765
KasperskyHEUR:Trojan.MSIL.Agent.gen
AlibabaTrojan:MSIL/Kryptik.0298e246
NANO-AntivirusTrojan.Win32.Kryptik.hpxoma
AegisLabTrojan.Win32.Malicious.4!c
TencentMsil.Trojan.Kryptik.Tdfw
Ad-AwareTrojan.GenericKD.43573765
EmsisoftTrojan.GenericKD.43573765 (B)
Comodofls.noname@0
F-SecureTrojan.TR/Kryptik.brdyg
DrWebTrojan.DownLoader34.14143
TrendMicroTrojan.MSIL.WACATAC.THHOEBO
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
CyrenW32/MSIL_Kryptik.BGS.gen!Eldorado
AviraTR/Kryptik.brdyg
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D298E205
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:MSIL/AgentTesla.VN!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Kryptik.R346697
ALYacTrojan.GenericKD.43573765
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of MSIL/Kryptik.XFB
TrendMicro-HouseCallTrojan.MSIL.WACATAC.THHOEBO
IkarusTrojan-Spy.MassLogger
eGambitUnsafe.AI_Score_90%
FortinetMSIL/GenKryptik.EPLL!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Generic/HEUR/QVM03.0.EF3C.Malware.Gen

How to remove MSIL/Kryptik.XFB?

MSIL/Kryptik.XFB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment