Malware

MSIL/Kryptik.OYM removal

Malware Removal

The MSIL/Kryptik.OYM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.OYM virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine MSIL/Kryptik.OYM?


File Info:

crc32: 3F6F749C
md5: cd22427fa3e4440c113e97938b878b61
name: CD22427FA3E4440C113E97938B878B61.mlw
sha1: 7399fdf59a695ad485896d879d31d9037c91750c
sha256: 745814224a9c23ecd49041459a215d63178859d2f12abecaf33f788f1797ccd5
sha512: 8d104d3a87f0fbd7e02d02ac32e671acb825ee3918758e7d3db7bc2f0e054ad2d9b0fcac40a6998abbe144c78c9aef03262189131a70389c8dab7aa0cffa6db2
ssdeep: 6144:CGsg/nPVu1+oPACnU23gWx2r+V4cAVQXHezLpSxCD:lf/nMb3Hx2cAVQ3coxC
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Kryptik.OYM also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3953
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Crysis
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.MSIL.Crypt.4
Cybereasonmalicious.fa3e44
CyrenW32/S-4ae8e800!Eldorado
SymantecDownloader
ESET-NOD32a variant of MSIL/Kryptik.OYM
APEXMalicious
KasperskyHEUR:Trojan-Ransom.Win32.Generic
MicroWorld-eScanGen:Variant.MSIL.Crypt.4
TencentWin32.Trojan.Generic.Szbe
Ad-AwareGen:Variant.MSIL.Crypt.4
SophosMal/Generic-S
ComodoMalware@#31tv8j9nbbqin
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.CryptDoma.fc
FireEyeGeneric.mg.cd22427fa3e4440c
EmsisoftGen:Variant.MSIL.Crypt.4 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Scarsi.bfa
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1138724
MicrosoftTrojan:Win32/Occamy.C74
AegisLabTrojan.Win32.Generic.j!c
GDataMSIL.Trojan-Ransom.Crysis.A
AhnLab-V3Trojan/Win32.Crusis.C2602497
McAfeeRDN/Ransom.dz
MAXmalware (ai score=95)
VBA32Trojan.Encoder
MalwarebytesRansom.Crysis
PandaTrj/RansomCrypt.E
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.OJV!tr
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HxQBEpsA

How to remove MSIL/Kryptik.OYM?

MSIL/Kryptik.OYM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment