Malware

About “MSIL/Kryptik.ZUB” infection

Malware Removal

The MSIL/Kryptik.ZUB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZUB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ZUB?


File Info:

crc32: BC21379A
md5: 6f98206e6905f1f727e255d114d3c0ac
name: 6F98206E6905F1F727E255D114D3C0AC.mlw
sha1: 71f6208364a668e72f8109a373c6c83c90b7999f
sha256: 97069c864ebe6a1a3e6e85bd1ff54351810cc32de3cdfe34f7fef15f04da0b87
sha512: 53e6e020fd5df48e7909c42c01e1fd565fe0107c0248c359b22394f67c0f3e8a67c1c7a59c70d9c964ad3d44963735505c69b7d242c3e688c9db4758db407703
ssdeep: 12288:ZSprUPZb4NuAvlTwvtonQkJzUOBjgQQiq62fo1:ZEU4NuA9QkyO2im2
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014
Assembly Version: 3.0.0.0
InternalName: SubcategoryMembershipEntry.exe
FileVersion: 3.0.0.0
CompanyName: KTV
LegalTrademarks:
Comments:
ProductName: KTVManagement
ProductVersion: 3.0.0.0
FileDescription: KTVManagement
OriginalFilename: SubcategoryMembershipEntry.exe

MSIL/Kryptik.ZUB also known as:

McAfeePWS-FCUC!6F98206E6905
CylanceUnsafe
SangforTrojan.Win32.Wacatac.D9
Cybereasonmalicious.364a66
CyrenW32/MSIL_Kryptik.COP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyHEUR:Trojan.MSIL.Taskun.gen
AlibabaTrojan:Win32/starter.ali1000139
F-SecureTrojan.TR/AD.AgentTesla.gafiy
McAfee-GW-EditionPWS-FCUC!6F98206E6905
SophosMal/Generic-S
WebrootW32.Trojan.Gen
AviraTR/AD.AgentTesla.gafiy
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Kryptik.ST!MTB
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataMSIL.Trojan-Stealer.AgentTesla.0B3JRK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AgentTesla.R357216
BitDefenderThetaGen:NN.ZemsilF.34590.Wm0@aeRFEYp
MalwarebytesTrojan.Crypt.MSIL
ESET-NOD32a variant of MSIL/Kryptik.ZUB
TencentWin32.Trojan.Inject.Auto
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_86%
FortinetMSIL/Kryptik.ZTX!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwMAhrkA

How to remove MSIL/Kryptik.ZUB?

MSIL/Kryptik.ZUB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment