Malware

MSIL/Kryptik.YAM removal guide

Malware Removal

The MSIL/Kryptik.YAM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YAM virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.YAM?


File Info:

crc32: 0F3CC267
md5: 36133b0f0237b7f645b3e34a33b79cc3
name: uzzu.exe
sha1: 71770da2d876bbbfbc6c7ee8ef671ac34d1bdb40
sha256: 5abc963a4cbaaee6582d5db264da8b2cb0c5a760115047a8df1e629c48dfc6e9
sha512: 78afcb84c4f46ea7bb4538fe1397581412215053c2abd4847f370bfdf7562c05d28cf1fd1f166c79939ddfd327fe2deddea261495de9ffcfc1be973f920678fa
ssdeep: 6144:SqSya0VNGj2Rnv/HCP4veQAdm1tTu8XjdGMTyX6RKihqvTrDt3/HUToajH6ifiSt:SqS/P4GlYIMIoNGNcfHL5ZP+wQVoBSX8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Stxe9phane Gasne (C) 2019
Assembly Version: 14.0.9.0
InternalName: bZkb.exe
FileVersion: 14.0.0.2
CompanyName: Stxe9phane Gasne
LegalTrademarks:
Comments:
ProductName: Tribunal de Grande Instance
ProductVersion: 14.0.0.2
FileDescription: Tribunal de Grande Instance
OriginalFilename: bZkb.exe

MSIL/Kryptik.YAM also known as:

MicroWorld-eScanTrojan.GenericKD.43990207
FireEyeGeneric.mg.36133b0f0237b7f6
McAfeePWS-FCRC!36133B0F0237
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Agensla.i!c
K7AntiVirusTrojan ( 0057053a1 )
BitDefenderTrojan.GenericKD.43990207
K7GWTrojan ( 0057053a1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTrojan.MSIL.WACATAC.THJOEBO
CyrenW32/MSIL_Kryptik.BVA.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/runner.ali1000123
NANO-AntivirusTrojan.Win32.Agensla.hyqdcb
Ad-AwareTrojan.GenericKD.43990207
SophosMal/Generic-S
ComodoMalware@#26bwukhsf729
DrWebTrojan.Inject4.2299
InvinceaMal/Generic-S
McAfee-GW-EditionPWS-FCRC!36133B0F0237
EmsisoftTrojan-Spy.Agent (A)
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.Swotter.emtpc
MicrosoftTrojan:MSIL/CryptInject.PB!MTB
ArcabitTrojan.Generic.D29F3CBF
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.43990207
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.MSIL.R352645
ALYacTrojan.Agent.FormBook
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/Agent.AJS
ESET-NOD32a variant of MSIL/Kryptik.YAM
TrendMicro-HouseCallTrojan.MSIL.WACATAC.THJOEBO
YandexTrojan.AvsArher.bTJEKx
IkarusTrojan.MSIL.Inject
eGambitUnsafe.AI_Score_69%
FortinetMSIL/Kryptik.YAM!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.2d876b
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.fc8

How to remove MSIL/Kryptik.YAM?

MSIL/Kryptik.YAM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment