Malware

MSIL/Kryptik.UYQ (file analysis)

Malware Removal

The MSIL/Kryptik.UYQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.UYQ virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.UYQ?


File Info:

crc32: ABFBFBF7
md5: 6bff3851479564cc90463a05ae73ec01
name: 6BFF3851479564CC90463A05AE73EC01.mlw
sha1: 6335a14597771d82d95bfb43391a8c7261337a30
sha256: 1a10be99f6a665092c4774795547d72582003a72daefd1307e571d2a11e18b6c
sha512: f9288a06e64ec4c1a2cfd2477e4d43852c745af1e33b041f129cd375f3e2d2b9bfe88f50b9c7ae8ceb8826f1703709af263dfa708ca0de7d87304148ca60bb2b
ssdeep: 1536:xrc2t+uipIZHWO369oJtRgqrgcnXMCOrOIcAL1lN6ma0Zzey9Xj39TjxZBSI1i:xI2VQIsOqyJtRgqW/O81v6yJd9JJy
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xc11cxcc98xadf8xbaa8xb4e0xc788xc2a4xbaa8xace0xd2b9xd2b9xc774xc11cxadf8xac00xace0xb140xc788xadf8xc2b5xbcc4xb2e4xc5d0xb2c8xb978xbaa8xadf8xadf8xb9acxace0xace0xc744xc774xb9acxc11cxcc98xc5d0xc990xb4e0xb978xac00xc6b0xadf8xc6b0xd2b9xace0xac00xace0xd2b9xc2a4xb2e4xac00xb140xb2e4xb978xbaa8xbaa8xbaa8xc2b5xc81cxb2e4xc2a4xace0xb978xb9acxc788xadf8xc81cxac00xc744xbaa8xb9acxc744xc744xb2e4xc2a4xc758xadf8xb140xcc98xb9acxb798xc6b0xc2b5xc218xbcc4xc758xc758xc990xc11cxc5d0xc758xc2a4xbaa8xb978xae38xc2b5xadf8xc2b5
Assembly Version: 1.0.0.0
InternalName: xb2e4xadf8xc990xcc98xc11cxb9acxb2e4xbaa8xb798.exe
FileVersion: 1.0.0.0
CompanyName: xb2e4xc758xc990xb4e0xc6b0xc990xb9acxadf8xd2b9xc81cxc2b5xbaa8xac00xace0xae38xc11cxd2b9xadf8xace0xb2e4xc6b0xadf8xbcc4xbaa8xc774xb9acxace0xc758xadf8xc788xadf8xc2b5xadf8xace0xb140xadf8xadf8xc11cxac00xc744xb798xc2b5xc218xc758xb978xc788xcc98xb2c8xc758xae38xbcc4xace0xc774xae38xc11cxb2e4xc5d0xcc98xc758xc2b5xb978xc11cxc218xbaa8xbcc4xbaa8xae38xc2b5xb9acxadf8xc11cxbcc4xace0xc744xb9acxace0xace0xace0xb4e0xc2b5xc758xadf8xb978xae38xadf8xb798xbaa8xb140xbcc4xbaa8xace0xd2b9xadf8xace0xcc98xbaa8xb9acxbaa8xc5d0
LegalTrademarks: xc744xc2b5xc774xc11cxc774xc11cxace0xd2b9xac00xc990xadf8xc2b5xc744xc6b0xc5d0xc758xbaa8xac00xc11cxcc98xb978xc2b5xb9acxc2b5xb2e4xc774xb9acxc2b5xc6b0xc218xc788xb140xc218xb140xb2e4xc774xb9acxc2b5xace0xc990xb9acxd2b9xc11cxb2c8xb9acxbcc4xc788xb2e4xc788xace0xd2b9xc11cxb2e4xb4e0xc6b0xadf8xc788xc2b5xc11cxb978xbaa8xb798xcc98xb4e0xb2c8xc11cxace0xc788xc788xc990xadf8xb2e4xc2b5xc6b0xc81cxc2a4xc788xbcc4xc2b5xc2b5xc6b0xd2b9xb9acxc758xc774xace0xc2b5xc218xb2c8xb2e4xc6b0xc990xcc98xace0xc788xc2b5xc6b0xace0xadf8
Comments: xb9acxb9acxb4e0xb2e4xd2b9xb2e4xb140xd2b9xbaa8xc218xb9acxc744xb9acxc788xc774xc788xb978xbaa8xc11cxc2a4xace0xb798xac00xc744xadf8xb2e4xadf8xc11cxadf8xb9acxc788xbaa8xace0xbcc4xc758xc774xc5d0xadf8xc218xbaa8xc6b0xb978xace0xc6b0xc774xac00xc218xb798xb9acxc758xace0xbaa8xd2b9xb4e0xb140xbaa8xd2b9xace0xadf8xc2b5xc11cxbaa8xbaa8xb9acxbaa8xb9acxd2b9xb2e4xbaa8xb978xb140xc6b0xadf8xbcc4xb2e4xc218xbcc4xc218xb9acxc758xbaa8xb4e0xae38xcc98xb9acxc81cxc744xc5d0xae38xb978xae38xc2b5xc788xac00xc2b5xbaa8xc2b5xadf8xc81c
ProductName: xc744xc5d0xc2b5xd2b9xb140xc2b5xb9acxc81cxc788xb2e4xc2b5xb9acxd2b9xd2b9xb4e0xb9acxc788xc788xc6b0xc6b0xb2e4xbcc4xb798xbcc4xc2b5xace0xb140xc788xbaa8xb9acxace0xc744xc2b5xc11cxc11cxc774xb140xb140xadf8xbaa8xcc98xc2b5xb798xc11cxae38xb9acxbcc4xace0xc6b0xc744xc744xb2e4xc774xc990xc758xadf8xace0xb9acxb9acxc6b0xace0xace0xc774xbcc4xbaa8xbaa8xc990xc11cxbcc4xbaa8xae38xb4e0xc788xc788xb9acxb9acxb2e4xbaa8xc744xc758xac00xb9acxac00xc218xc774xd2b9xbaa8xae38xace0xc990xae38xb9acxc218xc990xc788xc81cxc81cxb9acxb9ac
ProductVersion: 1.0.0.0
FileDescription: xb2e4xadf8xc990xcc98xc11cxb9acxb2e4xbaa8xb798
OriginalFilename: xb2e4xadf8xc990xcc98xc11cxb9acxb2e4xbaa8xb798.exe

MSIL/Kryptik.UYQ also known as:

K7AntiVirusTrojan ( 004ce6d41 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner2.16571
CynetMalicious (score: 99)
ALYacTrojan.Crypt.Gen.1
CylanceUnsafe
ZillyaTrojan.Crypt.Win32.43892
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Kryptik.fda102fc
K7GWTrojan ( 004ce6d41 )
Cybereasonmalicious.147956
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.UYQ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.Crypt.Gen.1
NANO-AntivirusTrojan.Win32.Agent.elgxdg
MicroWorld-eScanTrojan.Crypt.Gen.1
TencentMalware.Win32.Gencirc.114cf2ff
Ad-AwareTrojan.Crypt.Gen.1
SophosMal/Generic-S
ComodoMalware@#2w15n9j6pte55
BitDefenderThetaGen:NN.ZemsilF.34236.gq3@aKZ02Cm
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.6bff3851479564cc
EmsisoftTrojan.Crypt.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.jvnn
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.271B1E3
MicrosoftBackdoor:MSIL/Bladabindi
GDataTrojan.Crypt.Gen.1
AhnLab-V3Trojan/Win32.Bladabindi.R234586
McAfeeArtemis!6BFF38514795
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
YandexTrojan.Agent!RHHyzuEUKlQ
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.DLU!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.UYQ?

MSIL/Kryptik.UYQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment