Malware

MSIL/Kryptik.ACIA removal tips

Malware Removal

The MSIL/Kryptik.ACIA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ACIA virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ACIA?


File Info:

crc32: 43EF0822
md5: ff2de7af645bea1f0d0b2a1efad90ee9
name: FF2DE7AF645BEA1F0D0B2A1EFAD90EE9.mlw
sha1: a9db492ec5a4e676911909fb9db2709a7ef5598c
sha256: 7c995b2cba9072f5c246f333e7ad9b4302f836babf9fe90bab766251c432983d
sha512: 7504fb9cbecc27218beefcb72a3820328bca240e9c3a4ddee0577def884a97d204056504e635ba14624ada9ffe7486d6cc3b1b2dd06eef75e3434fa480ab6995
ssdeep: 24576:1CNBWDJGTDlp1JSQ4H43EpDlch7eBnuRDKe:KWVGTD31JGH43Epah6BnuR
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (c) X509EncryptingCredentials Corporation. All rights reserved.
Assembly Version: 570.149.255.530
InternalName: TreeNodeStyle.exe
FileVersion: 357.561.948.302
CompanyName: X509EncryptingCredentials Corporation.
Comments: SqlDataAdapter CompiledQuery Software.
ProductName: SqlDataAdapter CompiledQuery App.
ProductVersion: 357.561.948.302
FileDescription: SizeBox WorkflowInstanceAbortedRecord App
OriginalFilename: TreeNodeStyle.exe

MSIL/Kryptik.ACIA also known as:

LionicTrojan.MSIL.Reline.i!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.ec5a4e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ACIA
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
BitDefenderTrojan.GenericKD.46759813
MicroWorld-eScanTrojan.GenericKD.46759813
Ad-AwareTrojan.GenericKD.46759813
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34058.jn2@aODIHzd
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.ff2de7af645bea1f
EmsisoftTrojan.GenericKD.46759813 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/AD.RedLineSteal.xofct
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
ArcabitTrojan.Generic.D2C97F85
ZoneAlarmHEUR:Trojan-PSW.MSIL.Reline.gen
GDataMSIL.Trojan-Stealer.NetSteal.RQVS0O
McAfeeArtemis!FF2DE7AF645B
MAXmalware (ai score=99)
MalwarebytesMachineLearning/Anomalous.94%
IkarusWin32.Outbreak
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ACIA!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.ACIA?

MSIL/Kryptik.ACIA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment