Malware

MSIL/Kryptik.XZV (file analysis)

Malware Removal

The MSIL/Kryptik.XZV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.XZV virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.XZV?


File Info:

crc32: 1A9248EC
md5: 06f6128ed4fdab3b42dcf93388117de4
name: upload_file
sha1: ccce18f32a54bce9f4eacd467ab1a5573934733c
sha256: 96256638f3441f3b5c12e3fd667daa2cbbc1935300dc6ac2606fad8ced276d2e
sha512: f2369a354f5c882b0a9831ca8b1bc7047729d85be73396ed3690d45ed125e75b84635a5aef9ca709f96f2ac2bac08178f7700d763813e2fb291f38668284235e
ssdeep: 6144:j9977eJOHmW5ZOYd/RI9xylx8RG31E89nQAXAUItLgPUdbqvA:p9veoRzpIyKG3W8CAXW0Mdev
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2009 247CDA5EA34EDB?HG:7@8
Assembly Version: 1.0.0.0
InternalName: TEST13.exe
FileVersion: 6.10.13.16
CompanyName: 247CDA5EA34EDB?HG:7@8
Comments: 786=C?@J9<;=9D65
ProductName: =J6JFC5FGF;@FF4
ProductVersion: 6.10.13.16
FileDescription: =J6JFC5FGF;@FF4
OriginalFilename: TEST13.exe

MSIL/Kryptik.XZV also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43993608
FireEyeGeneric.mg.06f6128ed4fdab3b
McAfeeRDN/Generic PWS.y
CylanceUnsafe
AegisLabTrojan.MSIL.HiveMon.l!c
SangforMalware
K7AntiVirusTrojan ( 005703fc1 )
BitDefenderTrojan.GenericKD.43993608
K7GWTrojan ( 005703fc1 )
Cybereasonmalicious.32a54b
CyrenW32/MSIL_Kryptik.APR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Spy.MSIL.HiveMon.gen
AlibabaTrojanSpy:MSIL/Kryptik.b12ca993
ViRobotTrojan.Win32.Z.Wacatac.451072.F
Ad-AwareTrojan.GenericKD.43993608
EmsisoftTrojan.GenericKD.43993608 (B)
ComodoTrojWare.Win32.Agent.sraha@0
F-SecureTrojan.TR/Kryptik.pdjnu
DrWebTrojan.Siggen9.56514
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SophosMal/Generic-S
IkarusTrojan-Spy.HawkEye
AviraTR/Kryptik.pdjnu
MAXmalware (ai score=80)
MicrosoftTrojan:MSIL/Stealer.DR!MTB
ArcabitTrojan.Generic.D29F4A08
ZoneAlarmHEUR:Trojan-Spy.MSIL.HiveMon.gen
GDataTrojan.GenericKD.43993608
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.43993608
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.XZV
TrendMicro-HouseCallTROJ_GEN.R002H0CJ520
SentinelOneDFI – Malicious PE
FortinetW32/HiveMon.XZV!tr
BitDefenderThetaGen:NN.ZemsilF.34282.Bm0@a053Glc
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.Spy.700

How to remove MSIL/Kryptik.XZV?

MSIL/Kryptik.XZV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment