Malware

MSIL/Kryptik.ACAY malicious file

Malware Removal

The MSIL/Kryptik.ACAY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ACAY virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ACAY?


File Info:

crc32: 293799D3
md5: d6fa3b0d0ff9a556ba17b38db4990841
name: D6FA3B0D0FF9A556BA17B38DB4990841.mlw
sha1: 653679e14a1ad538f2ca62ca3b1f4a4110fb80f4
sha256: 97d1f00a9c4853e05bdad965148774ee6d3c58bcb864c018909d04ae99b9ed2e
sha512: 411aa9672d6fc4e27566ea85a4c884422c7a8a37c7939eac5b34399f3bd6093a45b2d50da84960ea2e600272daf2547315cf2a40cef09c77686fd09582d6191e
ssdeep: 12288:sdGkFw+NaOgKJfcpeuWnSI3qbcbi6A8ibsUbUfv:sfx2LnI3Nbt0srX
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017 F=@CB=?3;B;?A3J<?6B4?D:9
Assembly Version: 1.0.0.0
InternalName: uc eme.exe
FileVersion: 9.13.18.22
CompanyName: F=@CB=?3;B;?A3J<?6B4?D:9
Comments: 2A?=@;J832C756AB<H
ProductName: 8D>8>:;=C<2HC98H8A8A=G
ProductVersion: 9.13.18.22
FileDescription: 8D>8>:;=C<2HC98H8A8A=G
OriginalFilename: uc eme.exe

MSIL/Kryptik.ACAY also known as:

K7AntiVirusTrojan ( 0057f9f61 )
LionicTrojan.MSIL.Noon.l!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.43452
CynetMalicious (score: 99)
CAT-QuickHealTrojanpws.Msil
ALYacTrojan.GenericKD.37258298
CylanceUnsafe
SangforSpyware.MSIL.Noon.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/Tnega.cdff2215
K7GWTrojan ( 0057f9f61 )
Cybereasonmalicious.14a1ad
CyrenW32/Trojan.WJLG-5153
SymantecRansom.Wannacry
ESET-NOD32a variant of MSIL/Kryptik.ACAY
ZonerTrojan.Win32.115346
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.37258298
MicroWorld-eScanTrojan.GenericKD.37258298
TencentMsil.Trojan-qqpass.Qqrob.Wuhe
Ad-AwareTrojan.GenericKD.37258298
SophosMal/Generic-S + Troj/Steal-BTW
ComodoMalware@#29u40ztnb2a9v
BitDefenderThetaGen:NN.ZemsilCO.34058.Nm0@a8BCoSc
TrendMicroTrojanSpy.MSIL.NOON.USMANGJ21
McAfee-GW-EditionRDN/Generic PWS.y
FireEyeGeneric.mg.d6fa3b0d0ff9a556
EmsisoftTrojan.GenericKD.37258298 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Kryptik.iepye
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Tnega.BK!MTB
ArcabitTrojan.Generic.D238843A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.37258298
AhnLab-V3Trojan/Win.Tnega.C4561179
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MZCrypt.MSIL.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.NOON.USMANGJ21
YandexTrojan.Igent.bWfJkY.37
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.74499699.susgen
FortinetMSIL/Kryptik.ABWU!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwMArmkA

How to remove MSIL/Kryptik.ACAY?

MSIL/Kryptik.ACAY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment