Malware

MSIL/Kryptik.XCF information

Malware Removal

The MSIL/Kryptik.XCF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.XCF virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.XCF?


File Info:

crc32: CCE15E28
md5: 24e5b4ec3572f8e49dfa152e03c3f819
name: own.exe
sha1: 979c272491900248bea624a8a47fb08ecdec8146
sha256: 3c3a52620a36e8ef2806ffad5a241444d93b7eb839c3b3cfa4697e130d349dcc
sha512: 57b38bdd7a7460a534504d295fc20de5f389e13f299e85a414b12ef8539069378109215d4475c1f16282f54e9458e17e3fd5c433c9819a9542a04435ff1d1d7b
ssdeep: 12288:86gKg5i6sNEjrDSVueJogcUIDaKb0dVXpwm5L:oKg5hg4eTTID6dVKA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: gJtFY.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: WinFormsFirstOne
ProductVersion: 1.0.0.0
FileDescription: WinFormsFirstOne
OriginalFilename: gJtFY.exe

MSIL/Kryptik.XCF also known as:

MicroWorld-eScanTrojan.GenericKD.34250827
FireEyeGeneric.mg.24e5b4ec3572f8e4
Qihoo-360Generic/HEUR/QVM03.0.DF87.Malware.Gen
McAfeeFareit-FXO!24E5B4EC3572
CylanceUnsafe
BitDefenderTrojan.GenericKD.34250827
Cybereasonmalicious.491900
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.XCF
APEXMalicious
GDataTrojan.GenericKD.34250827
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaTrojan:MSIL/Generic.bf377703
AegisLabTrojan.Win32.Malicious.4!c
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.34250827
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.mfyiz
DrWebTrojan.PWS.Siggen2.52692
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.34250827 (B)
IkarusWin32.Outbreak
CyrenW32/MSIL_Kryptik.BFY.gen!Eldorado
WebrootW32.Malware.Gen
AviraTR/Kryptik.mfyiz
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D10DCC
AhnLab-V3Trojan/Win32.MSILKrypt.R346182
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftTrojan:MSIL/AgentTesla.VN!MTB
ALYacTrojan.GenericKDZ.69068
MAXmalware (ai score=85)
MalwarebytesSpyware.AgentTesla
PandaTrj/GdSda.A
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_74%
FortinetMSIL/Wacatac.C!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Kryptik.XCF?

MSIL/Kryptik.XCF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment