Malware

MSIL/Kryptik.SMR (file analysis)

Malware Removal

The MSIL/Kryptik.SMR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.SMR virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Kryptik.SMR?


File Info:

crc32: 2E13713E
md5: 7429f06635520b45c0ab7df2b0cfdef0
name: movecryp30k.exe
sha1: cd8ab59257cef63dd65f1ce51a22207d58a863d3
sha256: 5c374a09cb4ca9c17b81dbf2c26f1f633dedfadc828717c3e0a32bb2d9e8f01a
sha512: 80fedd1c15d21ad5d8532ddc0dd88852bcc4d7c75d9175b7120b8a9886af1820571f72db633727b7f2a9a4b22b03bfa562b67342786627cc5022df291051ac23
ssdeep: 12288:oeYHE+hrpwXGuJIdL7m6/pExg+9ic4KSena/:VYHE++GdL7mypogLc4KL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 0.0.0.0
InternalName: MoveCryp30k.exe
FileVersion: 8.12.17.21
CompanyName: ujozoyovopatohedufuzil
Comments: icesebupolaqeyigah
ProductName: aheqoguw
ProductVersion: 8.12.17.21
FileDescription: aheqoguw
OriginalFilename: MoveCryp30k.exe

MSIL/Kryptik.SMR also known as:

MicroWorld-eScanTrojan.GenericKD.41787321
FireEyeGeneric.mg.7429f06635520b45
CAT-QuickHealTrojan.MSIL
Qihoo-360Generic/Trojan.289
McAfeeRDN/generic.g
CylanceUnsafe
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005555561 )
BitDefenderTrojan.GenericKD.41787321
K7GWTrojan ( 005555561 )
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.41787321
KasperskyHEUR:Trojan.MSIL.Agent.gen
AlibabaTrojan:Win32/Malmail.ali1000112
NANO-AntivirusTrojan.Win32.Kryptik.fzfqox
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.41787321
EmsisoftTrojan.GenericKD.41787321 (B)
ComodoMalware@#3a55b8unbx4ab
F-SecureHeuristic.HEUR/AGEN.1043491
DrWebTrojan.PWS.Siggen2.27987
ZillyaTrojan.Kryptik.Win32.1738909
TrendMicroTrojanSpy.MSIL.NEGASTEAL.KDM
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
CyrenW32/MSIL_Kryptik.NA.gen!Eldorado
JiangminTrojan.MSIL.mpvy
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1043491
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D27D9FB9
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:Win32/Skeeyah.HK!MTB
AhnLab-V3Trojan/Win32.Agent.R291597
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34090.Qm0@aK4aCVc
ALYacTrojan.GenericKD.41787321
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.RMCrypt.MSIL.Generic
PandaTrj/Genetic.gen
ESET-NOD32a variant of MSIL/Kryptik.SMR
TrendMicro-HouseCallTrojanSpy.MSIL.NEGASTEAL.KDM
TencentMsil.Trojan.Agent.Aext
YandexTrojan.Kryptik!c0bVwaWr0ys
SentinelOneDFI – Malicious PE
FortinetMSIL/Kryptik.SNE!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.257cef
AvastWin32:Trojan-gen
MaxSecureTrojan.Malware.1728101.susgen

How to remove MSIL/Kryptik.SMR?

MSIL/Kryptik.SMR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment