Malware

MSIL/Kryptik.XRZ malicious file

Malware Removal

The MSIL/Kryptik.XRZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.XRZ virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.XRZ?


File Info:

crc32: 2EC4976C
md5: d18f6b24885e21a55d4c030832cde205
name: D18F6B24885E21A55D4C030832CDE205.mlw
sha1: 50a6a4371234e04113e33ba938778ef50fbae1d4
sha256: 726e779529f34143e4d094f0252f3c6e04547d062970d26c0cb553c57c98b1ed
sha512: 2a92bdfeb93ee5d5932bef80e9291ba76126c0e9102d1029d649d5458e54dd50ab477388a1dd4b897458e9947135c89a4ac7e7a538cdef18c76112f70d2d3908
ssdeep: 6144:GjSVAffHPxtvJ/xanJH2fSYoMa2MgNZk9FtxyWU+gf+KTo0hsBTB:GjxXvjFxiTYbNZoF2WHmVBs
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: Hospital.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Hospital
ProductVersion: 1.0.0.0
FileDescription: Hospital
OriginalFilename: Hospital.exe

MSIL/Kryptik.XRZ also known as:

Elasticmalicious (high confidence)
MalwarebytesMachineLearning/Anomalous.97%
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Kryptik.ali2000016
Cybereasonmalicious.71234e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.XRZ
APEXMalicious
AvastFileRepMalware
CynetMalicious (score: 100)
KasperskyUDS:Trojan-PSW.MSIL.Stealer.gen
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.d18f6b24885e21a5
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/AgentTesla!ml
McAfeeArtemis!D18F6B24885E
TrendMicro-HouseCallTROJ_GEN.F0D1C00HO21
IkarusWin32.Outbreak
FortinetMSIL/Kryptik.ZXO!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove MSIL/Kryptik.XRZ?

MSIL/Kryptik.XRZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment