Malware

MSIL/GenKryptik.BYJO (file analysis)

Malware Removal

The MSIL/GenKryptik.BYJO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.BYJO virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

h4x000r.duckdns.org

How to determine MSIL/GenKryptik.BYJO?


File Info:

crc32: F997CDD4
md5: 3b7e086578585d8855215cd89f574395
name: 3B7E086578585D8855215CD89F574395.mlw
sha1: ab1928a69daca0629550acd3e9ac14e725571b41
sha256: 995ba77a23edf035ab3a8d3aa81bc03a2341f2e78c4a798433ab0b09015f91cb
sha512: 6a77fdca7ef3f29fe9ac72ea0ebc5c1d17694cc95795753d0f920bd2b0196c93dc1de7a170aaffa18685e518dd313b75e86be490622c58bad6f120a194baee13
ssdeep: 3072:iO0S5qB27i4i91s9ohzlS0NegAFCCEO9U7D1ErRRrUVWGs92ea4nKBR/ihnZ:900pi91s9Uz
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: E09E5DD0524D44504B4CFFABC0.exe
FileVersion: 1.0.0.0
ProductName: E09E5DD0524D44504B4CFFABC0
ProductVersion: 1.0.0.0
FileDescription: E09E5DD0524D44504B4CFFABC0
OriginalFilename: E09E5DD0524D44504B4CFFABC0.exe

MSIL/GenKryptik.BYJO also known as:

K7AntiVirusTrojan ( 0052f6db1 )
LionicTrojan.MSIL.Revenge.4!c
DrWebTrojan.Inject3.8562
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.30678778
CylanceUnsafe
ZillyaTrojan.Generic.Win32.704474
SangforTrojan.Win32.Tiggre.rfn
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Revenge.c6e3b689
K7GWTrojan ( 0052f6db1 )
Cybereasonmalicious.578585
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.BYJO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.MSIL.Revenge.cha
BitDefenderTrojan.GenericKD.30678778
NANO-AntivirusTrojan.Win32.Revenge.fayase
MicroWorld-eScanTrojan.GenericKD.30678778
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.30678778
SophosMal/Generic-S
ComodoMalware@#21qgjhdr2ecyl
BitDefenderThetaGen:NN.ZemsilF.34266.jm0@aGW2zNl
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103C919
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.3b7e086578585d88
EmsisoftTrojan.GenericKD.30678778 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.jaoa
WebrootW32.Malware.Gen
AviraTR/Dropper.MSIL.jfuft
eGambitUnsafe.AI_Score_83%
Antiy-AVLTrojan/Generic.ASMalwS.25F1DA8
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Generic.D1D41EFA
GDataTrojan.GenericKD.30678778
McAfeeArtemis!3B7E08657858
MAXmalware (ai score=98)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103C919
YandexTrojan.Revenge!bHV2iGr2PXg
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.BYGP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/GenKryptik.BYJO?

MSIL/GenKryptik.BYJO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment