Malware

MSIL/Kryptik.ACIU (file analysis)

Malware Removal

The MSIL/Kryptik.ACIU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ACIU virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ACIU?


File Info:

crc32: AD829167
md5: 2d50222f6b702083c73d10e94eaaef9f
name: 2D50222F6B702083C73D10E94EAAEF9F.mlw
sha1: dcce81eecbb46ef3963c8b4ad30f2ec3b14d2056
sha256: 80752bd3e74c165e9c88fee2b806b67641f6cdae222d4ef9f5bc433f8501e767
sha512: 10482897831ef7cf9ffc117e41e876c212f26c2f6cc4a8e089ee3990f64dde296d4d3c5fa5bcdab9c4f01ce71a4f864d43876c6f23f5fd2f64f97e66a50dcdfa
ssdeep: 24576:rRzS4127aD0WEjwizMRjgynPEeyTYQ/MuRJNObPztSC:I412GD0WEkihNYQZBObn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (c) BasicHttpsSecurity Corporation. All rights reserved.
Assembly Version: 802.786.379.740
InternalName: XamlObjectReader.exe
FileVersion: 685.509.998.574
CompanyName: BasicHttpsSecurity Corporation.
Comments: EdmComplexPropertyAttribute ActivityCodeDomSerializer Software.
ProductName: EdmComplexPropertyAttribute ActivityCodeDomSerializer App.
ProductVersion: 685.509.998.574
FileDescription: ProjectStartedEventHandler ImageButton App
OriginalFilename: XamlObjectReader.exe

MSIL/Kryptik.ACIU also known as:

LionicTrojan.MSIL.Stealer.l!c
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ACIU
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Spy.MSIL.Stealer.gen
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34058.en2@aOkM69b
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.2d50222f6b702083
SentinelOneStatic AI – Malicious PE
AviraTR/AD.RedLineSteal.pabfk
MicrosoftTrojan:Win32/AgentTesla!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
McAfeeArtemis!2D50222F6B70
MalwarebytesSpyware.PasswordStealer.MSIL.Generic
TrendMicro-HouseCallTROJ_GEN.R002H0DHC21
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ACIU!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Heur.Generic.HwMANjcA

How to remove MSIL/Kryptik.ACIU?

MSIL/Kryptik.ACIU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment