Malware

Should I remove “MSIL/Kryptik.ACJA”?

Malware Removal

The MSIL/Kryptik.ACJA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ACJA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Detects the presence of Wine emulator via function name
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a registry key
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ACJA?


File Info:

crc32: 3D899B8A
md5: 5905bb54207bcbad09a79ac1b228287d
name: 5905BB54207BCBAD09A79AC1B228287D.mlw
sha1: b85ea1fb73ca82326e74d7dd5d9e1f83ae37299d
sha256: 8da1066696aeab5cb8bfa44fdf59d246b51757eee8ea2b34618d1e75c54c99d8
sha512: 98be30715a0c7b317f3d13dac41200a7a47dacaf6013b12aa53e3ad3a18977f1e1116d3b1117e138e012fd3eb3d183d7eacc10244eac5a2fccb5e361ba1fc8e8
ssdeep: 24576:qAPp9AR95w0giWlq0CZ1siDrJwZuSUbqP:qAPpKRw0gFYb1si6ZpT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.4.0.0
InternalName: ObjectIDGenerat.exe
FileVersion: 1.4
CompanyName:
LegalTrademarks:
Comments:
ProductName: StarPlayerPC
ProductVersion: 1.4
FileDescription: StarPlayerPCx2122
OriginalFilename: ObjectIDGenerat.exe

MSIL/Kryptik.ACJA also known as:

LionicTrojan.MSIL.Agensla.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.964
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.b73ca8
CyrenW32/MSIL_Kryptik.EBN.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ACJA
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.37376503
MicroWorld-eScanTrojan.GenericKD.37376503
Ad-AwareTrojan.GenericKD.37376503
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.5905bb54207bcbad
EmsisoftTrojan.GenericKD.37376503 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1142734
eGambitUnsafe.AI_Score_55%
MicrosoftTrojan:Win32/AgentTesla!ml
GDataMSIL.Trojan-Stealer.AgentTesla.AIY880
McAfeeArtemis!5905BB54207B
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.F0D1C00HA21
YandexTrojan.AvsArher.bTJEKx
IkarusWin32.SuspectCrc
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FIQW!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.AgentTesla.HwMALT8A

How to remove MSIL/Kryptik.ACJA?

MSIL/Kryptik.ACJA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment