Malware

Win32/Kryptik.MSN removal

Malware Removal

The Win32/Kryptik.MSN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.MSN virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Kryptik.MSN?


File Info:

name: BDB6AC701F2CA8B4DF82.mlw
path: /opt/CAPEv2/storage/binaries/b71b24b2352cafda326c25460c337438432b69dbbbd150ad3ce181c2a5b03a0e
crc32: F08AB3C7
md5: bdb6ac701f2ca8b4df825801e784b8b7
sha1: 09dacd82c99a0eb1967f07b41446338006644264
sha256: b71b24b2352cafda326c25460c337438432b69dbbbd150ad3ce181c2a5b03a0e
sha512: 84b7bb6528c05656d35ea73c8aa528faba21cc3f0c516e896efc27735b11c1f13bf455ae75ad3123689f6c4196ea14e579c467dd1d4a3d376e52aa19be5cc077
ssdeep: 3072:XSjdyPt7LmjY5BQfo93kKA6mOtHI/23BgRaweFlW93EyP66dY1s0X0XdVbCIqo:9mjCxApOO/Nk/0NEKNdY1aLbCVo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162F3029EA9C0BDB0E8231F3CA95660D25BA9D4026E46F21FB71C0A2DDE6DC550E43791
sha3_384: 713ade8df6f710461157d4c74df173c8f1d0583f9d2cb111716701bacb17d4a93ee3b1de9a366c486cd5e656195435b4
ep_bytes: 83fe0074068d3d035040008b1d0e5040
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Kryptik.MSN also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.CodecPack.lmCO
MicroWorld-eScanGen:Heur.Conrox.2
FireEyeGeneric.mg.bdb6ac701f2ca8b4
CAT-QuickHealTrojan.Renos.PG
SkyhighBehavesLike.Win32.Eggnog.ch
McAfeeDownloader-CEW.ao
ZillyaTrojan.FakeAV.Win32.58431
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005485311 )
AlibabaRiskWare:Win32/FlashApp.040b2f07
K7GWTrojan ( 00244e321 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Letter.Z
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.MSN
APEXMalicious
ClamAVWin.Trojan.Fakeav-89111
KasperskyHoax.Win32.FlashApp.clzz
BitDefenderGen:Heur.Conrox.2
NANO-AntivirusTrojan.Win32.CodecPack.cbdhz
SUPERAntiSpywareTrojan.Agent/Gen-FraudPack
AvastWin32:Downloader-GPM [Trj]
TencentMalware.Win32.Gencirc.115a5b88
EmsisoftGen:Heur.Conrox.2 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen2
DrWebTrojan.Fakealert.46433
VIPREGen:Heur.Conrox.2
TrendMicroTROJ_KRYPTK.SMCA
Trapminemalicious.high.ml.score
SophosMal/FakeAV-NJ
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=99)
GDataGen:Heur.Conrox.2
JiangminTrojan/Jorik.efx
WebrootW32.Renos.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen2
VaristW32/FakeAlert.NH.gen!Eldorado
Antiy-AVLHackTool[Hoax]/Win32.FlashApp
KingsoftWin32.NotVirus.FlashApp.clzz
XcitiumTrojWare.Win32.Kryptik.BBTC@3gm7sg
ArcabitTrojan.Conrox.2
ZoneAlarmHoax.Win32.FlashApp.clzz
MicrosoftTrojanDownloader:Win32/Renos.PG
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Fakeav37.Gen
BitDefenderThetaGen:NN.ZexaF.36744.kCW@aCugymkc
TACHYONJoke/W32.FlashApp.169984
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
PandaTrj/Kryptik.D
TrendMicro-HouseCallTROJ_KRYPTK.SMCA
RisingDownloader.Renos!8.1D0 (TFE:2:LvPk7Xql4PL)
IkarusTrojan.Fakeav
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.AR!tr
AVGWin32:Downloader-GPM [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Kryptik.MSN?

Win32/Kryptik.MSN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment