Malware

How to remove “MSIL/Kryptik.ACUY”?

Malware Removal

The MSIL/Kryptik.ACUY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ACUY virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

wpad.local-net

How to determine MSIL/Kryptik.ACUY?


File Info:

name: D60CE5D660E7558CCB33.mlw
path: /opt/CAPEv2/storage/binaries/8f7ccb7c7764ca2467c8af4f22875d21ac1e070754863be9cc6ee3c479bbde08
crc32: 6D28A967
md5: d60ce5d660e7558ccb3306875696cb07
sha1: 9630c031e4bca46e6fc49748f95f4bbf11cb5554
sha256: 8f7ccb7c7764ca2467c8af4f22875d21ac1e070754863be9cc6ee3c479bbde08
sha512: a377421f9021a51b32f0480e74f9f16be930dc8fc379e90823421998879ed79b4c78f6913fdc94bbcc86e661507fc3160f4ccb429ba7cfbfb596b876d3626c10
ssdeep: 3072:TocP/1n8Y37gbIl4PVNBpVyz6gwA5rf7hWovrEToTaJkE490:8cPd8q7gbII/bgwAljAovoToTaJkE
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1A214927935D0F29FC416C47DC9547CF4AA646CEACE0A810BEC533D99B93C9F68A314A2
sha3_384: f16a3f9a977c7bdd9dfb43a20a9c21ffb7478a58e321f23f054e283e39f8502ff235c95297d16364899e597b14f08543
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-07-25 21:49:20

Version Info:

Translation: 0x0000 0x04b0
Comments: Windows Security notification icon
CompanyName: Microsoft® Windows® Operating System
FileDescription: SecurityHealthSystray
FileVersion: 10.0.19041.1 (WinBuild
InternalName: SecurityHealthSystray.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: SecurityHealthSystray.exe
ProductName: Microsoft Corporation
ProductVersion: 10.0.19041.1 (WinBuild
Assembly Version: 0.0.0.0

MSIL/Kryptik.ACUY also known as:

LionicTrojan.MSIL.Tasker.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.46689421
FireEyeTrojan.GenericKD.46689421
ALYacTrojan.GenericKD.46689421
CylanceUnsafe
ZillyaTrojan.Tasker.Win32.3529
CrowdStrikewin/malicious_confidence_80% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ACUY
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Tasker.gen
BitDefenderTrojan.GenericKD.46689421
TencentMsil.Trojan.Tasker.Wopo
Ad-AwareTrojan.GenericKD.46689421
SophosGeneric PUA JG (PUA)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WGT21
EmsisoftTrojan.GenericKD.46689421 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.46689421
AviraTR/Tasker.dsenf
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4562948
McAfeeArtemis!D60CE5D660E7
MAXmalware (ai score=84)
VBA32Trojan.MSIL.Tasker
MalwarebytesTrojan.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002C0WGT21
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Tasker!tr
AVGWin64:CoinminerX-gen [Trj]
AvastWin64:CoinminerX-gen [Trj]

How to remove MSIL/Kryptik.ACUY?

MSIL/Kryptik.ACUY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment