Malware

MSIL/Kryptik.OHQ malicious file

Malware Removal

The MSIL/Kryptik.OHQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.OHQ virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.OHQ?


File Info:

crc32: A9B0EF7D
md5: d2bf3e6790adcdd2d33c9e2edb0c4f5a
name: D2BF3E6790ADCDD2D33C9E2EDB0C4F5A.mlw
sha1: e46b5dbf060cd08999adce8d0a3125adcb8a82fc
sha256: e3df75eda0f3fff88f4ab98a687f7ec50b1adde27dbb1bb0947f96892eebf493
sha512: 51bb3781827a8ebf029a842e9644f08ddfe650a719af71c6d004896b584f165517eb6b71f35a657e797dfb4842f844d67d7b493acf6255f89dbb38be6e2abda8
ssdeep: 24576:22G/nvxW3Wzt0Mz7/JGxk9k+JbTY/X5IarO9H5oyOgQ8BrpFrZ5QYf3GSIMGW1sm:2bA3Ybz7/JbqF/XPOp5oH8fFfaWOm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MSIL/Kryptik.OHQ also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005334fc1 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.38227
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agenttesla
ALYacBackdoor.RAT.DC
CylanceUnsafe
SangforTrojan.Win32.AgentTesla.ml
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanSpy:MSIL/Stealer.44e3156c
K7GWTrojan ( 005334fc1 )
Cybereasonmalicious.f060cd
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.OHQ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.MSIL.Stealer.bqi
BitDefenderTrojan.GenericKD.37237565
MicroWorld-eScanTrojan.GenericKD.37237565
Ad-AwareTrojan.GenericKD.37237565
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.yxwhr@0
BitDefenderThetaGen:NN.ZemsilF.34796.Zo0@aeIfPkn
TrendMicroTROJ_GEN.R002C0WGH21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.d2bf3e6790adcdd2
EmsisoftTrojan.GenericKD.37237565 (B)
SentinelOneStatic AI – Malicious SFX
AviraTR/Dropper.MSIL.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
ArcabitTrojan.Generic.D238333D
GDataTrojan.GenericKD.37237565
AhnLab-V3Malware/Win32.RL_Trojanspy.R365095
McAfeeArtemis!D2BF3E6790AD
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.PasswordStealer.MSIL
TrendMicro-HouseCallTROJ_GEN.R002H0DGE21
RisingTrojan.FakeChrome!1.9C7B (CLASSIC)
IkarusTrojan.MSIL.CryptoObfuscator
FortinetMSIL/Generic.AP.13A3C6!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Generic.HwYDmWMA

How to remove MSIL/Kryptik.OHQ?

MSIL/Kryptik.OHQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment