Malware

What is “Heur.MSIL.Krypt.11 (B)”?

Malware Removal

The Heur.MSIL.Krypt.11 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.MSIL.Krypt.11 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

bot.whatismyipaddress.com

How to determine Heur.MSIL.Krypt.11 (B)?


File Info:

crc32: 11FA646F
md5: 2cc7ffe5675347906bfb3aae9cbbe363
name: 2CC7FFE5675347906BFB3AAE9CBBE363.mlw
sha1: 318c3e77aaed34423aaf4371d4ccb2ea3e49765e
sha256: bcd42f72eed908f1765d7a0dc7ef0ad6d7b3ef63f030afed7887ffd23ce1b937
sha512: 4f4f1f56efc73d5927db2db2243c49857b57665885461361c22a08e89adbde8c83293273ad8f8786fafd83fd9545cb6b92a601df2c10d2be3586618ccb2d9214
ssdeep: 3072:a0A3r0YVczzQ6moCj/RECjLG4PgIl1EcC8rv7h+Zif97o:COmHvpY4106jYZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: u5um4u2lj
Assembly Version: 765.959.49.502
InternalName: tmpE3D4.tmp
FileVersion: 833.836.334.446
CompanyName: t3yhi6hfd
LegalTrademarks: 4agekqm
Comments: up16iy5
ProductName: yzxlx57v
ProductVersion: 833.836.334.446
FileDescription: yq31cvh
OriginalFilename: tmpE3D4.tmp

Heur.MSIL.Krypt.11 (B) also known as:

LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
McAfeeArtemis!2CC7FFE56753
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.20439
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.567534
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.fbma
BitDefenderGen:Heur.MSIL.Krypt.11
NANO-AntivirusTrojan.Win32.Blocker.dcyppe
MicroWorld-eScanGen:Heur.MSIL.Krypt.11
TencentWin32.Trojan.Blocker.Huzv
Ad-AwareGen:Heur.MSIL.Krypt.11
SophosML/PE-A
ComodoMalware@#3sap9ahzpj02z
BitDefenderThetaGen:NN.ZemsilF.34050.im0@a0SXU5o
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.2cc7ffe567534790
EmsisoftGen:Heur.MSIL.Krypt.11 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Barys.16474.19
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.B022AF
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Heur.MSIL.Krypt.11
AhnLab-V3Trojan/Win32.Injector.C546418
MAXmalware (ai score=85)
PandaTrj/CI.A
FortinetW32/Blocker.FBMA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwMAEpsA

How to remove Heur.MSIL.Krypt.11 (B)?

Heur.MSIL.Krypt.11 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment