Malware

MSIL/Kryptik.XVN malicious file

Malware Removal

The MSIL/Kryptik.XVN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.XVN virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.XVN?


File Info:

crc32: 886744E9
md5: 0d24c1c7dd21c01170bcec87653aba0b
name: upload_file
sha1: 5acc6cfbebd22685f9205975938793692f3ff628
sha256: fc4b29f54e0b3ed0493ba85310a2665ab47e5143f3cb3ce09686f0560dd1ed04
sha512: 29158c2d7c6a74ddb2c7d2b8e55c72da1347348091a0b18f90ec33be6d45181a47304786433ce0b2d0bc67ef7daaeb826ae2b4c486e29ffb8e5238b899d6d024
ssdeep: 3072:4mqqgGn512pQjY3Az90WipyVsMawcvElWjVcbOztVD:UqgG5126yS0r4hawUEMcbOj
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: x5f00x8feax8feax5f00x5f00x5f00x514bx5409x514bx8feax8feax8feax8feax7ef4x5409x5f00x8feax5f00x8feax5f00x5f00x5409x8feax5f00x514bx5f00x5f00x7ef4x5f00
Assembly Version: 2.3.2.6
FileVersion: 0.5.1.2
CompanyName: x514bx7ef4x514bx7ef4x514bx8feax5409x7ef4x5f00x8feax7ef4x8feax5f00x7ef4x5f00x514bx5409x8feax514bx8feax8feax8feax5f00x8feax8feax5f00x5f00x5409
LegalTrademarks: x8feax514bx7ef4x7ef4x5f00x7ef4x8feax7ef4x7ef4x5f00
Comments: x5f00x8feax5f00x7ef4x5f00x8feax5f00x8feax8feax5f00
ProductName: x5f00x7ef4x5f00x5f00x5409x8feax8feax8feax514bx514bx7ef4x514bx514bx8feax5409x5f00x8feax514bx514bx5409x5f00
ProductVersion: 2.3.2.6
FileDescription: x8feax7ef4x5409x8feax514bx5f00x514bx5f00x5409x5f00
OriginalFilename: x5f00x7ef4x5f00x5f00x5409x8feax8feax8feax514bx514bx7ef4x514bx514bx8feax5409x5f00x8feax514bx514bx5409x5f00.exe
Translation: 0x0409 0x0514

MSIL/Kryptik.XVN also known as:

DrWebTrojan.Siggen10.27804
MicroWorld-eScanTrojan.GenericKD.34586205
Qihoo-360Generic/Trojan.Spy.78a
ALYacTrojan.PSW.AveMaria
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056f57b1 )
BitDefenderTrojan.GenericKD.34586205
K7GWTrojan ( 0056f57b1 )
BitDefenderThetaGen:NN.ZemsilF.34254.lm1@aWgmNmji
CyrenW32/Trojan.KUED-8911
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Spy.MSIL.AveMaria.gen
AlibabaTrojanSpy:MSIL/Kryptik.ab36e568
ViRobotTrojan.Win32.Z.Kryptik.193872.B
AegisLabTrojan.MSIL.AveMaria.l!c
RisingTrojan.Kryptik!8.8 (TFE:C:N8GeeRrJmNS)
Ad-AwareTrojan.GenericKD.34586205
SophosMal/Generic-S
ComodoMalware@#imwxkzylhamr
F-SecureTrojan.TR/Dropper.MSIL.guhwq
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionPWS-FCQU!0D24C1C7DD21
FireEyeTrojan.GenericKD.34586205
EmsisoftTrojan.GenericKD.34586205 (B)
IkarusTrojan.MSIL.Crypt
WebrootW32.Trojan.Gen
AviraTR/Dropper.MSIL.guhwq
MicrosoftTrojan:Win32/Ymacco.AAFC
ArcabitTrojan.Generic.D20FBE5D
ZoneAlarmHEUR:Trojan-Spy.MSIL.AveMaria.gen
GDataTrojan.GenericKD.34586205
McAfeePWS-FCQU!0D24C1C7DD21
MAXmalware (ai score=80)
MalwarebytesBackdoor.AveMaria
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.XVN
TencentWin32.Trojan.Falsesign.Frw
FortinetMSIL/Kryptik.XVV!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove MSIL/Kryptik.XVN?

MSIL/Kryptik.XVN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment