Malware

Should I remove “MSIL/Kryptik.CHS”?

Malware Removal

The MSIL/Kryptik.CHS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.CHS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.CHS?


File Info:

crc32: 3AC4A2E1
md5: faab2e7d3935200cae0daa5955db6cad
name: FAAB2E7D3935200CAE0DAA5955DB6CAD.mlw
sha1: ddb8d09791e4701bfcf5df630068d9d127b2af25
sha256: 601313857d18deeae7f2f8007431f72b54370e4f4031eb28451499772b037364
sha512: bf1a2fb240caf9774889ed356c8905acad2abfbc02ce7865cda3d85faa1865dfcdc200ef35f910dbc69f2bb437214811f7b00dfce492ebeda0590e20c624baa9
ssdeep: 3072:Ec5poPGdUjd012Mge7GHKjTFACxvNax86n8jg/cmJk3c5aue8SuIMAECheLFne5:EYGPFe8LAECiFeWEUDDDDDDDDgKNX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2018
Assembly Version: 1.0.0.0
InternalName: System.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: System
ProductVersion: 1.0.0.0
FileDescription: System
OriginalFilename: System.exe

MSIL/Kryptik.CHS also known as:

K7AntiVirusTrojan ( 00531c971 )
CynetMalicious (score: 100)
ALYacIL:Trojan.MSILZilla.5886
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1492146
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.ae7cc419
K7GWTrojan ( 00531c971 )
Cybereasonmalicious.d39352
CyrenW32/MSIL_Troj.DL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.CHS
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderIL:Trojan.MSILZilla.5886
MicroWorld-eScanIL:Trojan.MSILZilla.5886
Ad-AwareIL:Trojan.MSILZilla.5886
SophosMal/Generic-R + Mal/FakeMS-S
F-SecureHeuristic.HEUR/AGEN.1120344
BitDefenderThetaGen:NN.ZemsilF.34236.qm0@a8BSxwc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.faab2e7d3935200c
EmsisoftIL:Trojan.MSILZilla.5886 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1120344
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Dynamer
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitIL:Trojan.MSILZilla.D16FE
GDataIL:Trojan.MSILZilla.5886
AhnLab-V3Backdoor/Win.Generic.C4597861
McAfeeRDN/Generic.rp
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
YandexTrojan.Kryptik!evwzcds4+1g
IkarusBackdoor.Win32.DarkKomet
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.JCW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.CHS?

MSIL/Kryptik.CHS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment