Malware

MSIL/Kryptik.UWO removal instruction

Malware Removal

The MSIL/Kryptik.UWO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.UWO virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of iSpy Keylogger
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

z.whorecord.xyz
a.tomx.xyz
bot.whatismyipaddress.com

How to determine MSIL/Kryptik.UWO?


File Info:

crc32: 6632FE28
md5: df16a99b34fc3624d0be6f13202c29e3
name: chi.exe
sha1: f6d749f3e1937efa42f1edd0d85e9adbd98649ea
sha256: 104bb4cfe6c1b9614ee6fe3e83de994cbc691e8518655edcee8f9ab0b3171f6d
sha512: 8755d1af06b1ce0b5a8ab81924fab614859ccebed2b3c3bb641880aeed5a7e686de55c24e7dce1d0e3e9d3d451deeb99ecd568a0c04127bdae2393fcd4b5c4b6
ssdeep: 12288:UCHfGSwy+efQrqO/VQGZKxidIp/pNd5/JMN0FmyQhzLItDnOJM5zXzhemb+:UCHfQy+V5d9KxYIdW0UhiniM5rzq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 x58a8x4e91x8f6fx4ef6 2013
Assembly Version: 1.2.0.0
InternalName: HaxrRHEXgC.exe
FileVersion: 1.2.0.0
CompanyName: x51afx5929x6587
LegalTrademarks: x58a8x4e91x8f6fx4ef6
Comments: x58a8x4e91x8f6fx4ef6-x6570x72ecx8ba1x7b97x5668x63a7x4ef6
ProductName: SudokuCalcs
ProductVersion: 1.2.0.0
FileDescription: SudokuCalcs
OriginalFilename: HaxrRHEXgC.exe

MSIL/Kryptik.UWO also known as:

MicroWorld-eScanTrojan.GenericKD.33501440
FireEyeGeneric.mg.df16a99b34fc3624
McAfeeRDN/Generic.dx
ALYacTrojan.GenericKD.33501440
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056199d1 )
BitDefenderTrojan.GenericKD.33501440
K7GWTrojan ( 0056199d1 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZemsilF.34098.3m0@aO4dpSh
F-ProtW32/MSIL_Agent.BCO.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.UWO
TrendMicro-HouseCallTROJ_GEN.R011C0PC420
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKD.33501440
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Kryptik.fa911606
ViRobotTrojan.Win32.Z.Malpack.912384
AegisLabTrojan.Multi.Generic.4!c
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.trckm
DrWebTrojan.Siggen9.16936
TrendMicroTROJ_GEN.R011C0PC420
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33501440 (B)
CyrenW32/MSIL_Agent.BCO.gen!Eldorado
AviraTR/Kryptik.trckm
MAXmalware (ai score=89)
ArcabitTrojan.Generic.D1FF3100
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
MicrosoftTrojan:Win32/Occamy.C
Ad-AwareTrojan.GenericKD.33501440
MalwarebytesTrojan.MalPack.VND
PandaTrj/GdSda.A
TencentMsil.Trojan-qqpass.Qqrob.Wsju
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.74499699.susgen
FortinetMSIL/Kryptik.EFKZ!tr
WebrootW32.Trojan.Gen
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.d23

How to remove MSIL/Kryptik.UWO?

MSIL/Kryptik.UWO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment