Malware

MSIL/Kryptik.AYC malicious file

Malware Removal

The MSIL/Kryptik.AYC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AYC virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.AYC?


File Info:

crc32: 2BF21ED2
md5: 51a1593bb9c47923b72152007b95f769
name: 51A1593BB9C47923B72152007B95F769.mlw
sha1: 68a693ff02b9fa1ef18880195510e7fd7fd6a847
sha256: f050657a44280d2415298c64388cf467a1629a1703e9f911125d6bc7986b85e7
sha512: 20ab361013c230098e49e684097eb8f32c687d1c84a72174ea554cb7ba0a606af3efd5ac5b16111ed4e3ed133f1f6dfa7dd984b3f31aa8051aab094f41f7c3d0
ssdeep: 12288:eR4CSslQ91naOCItXeArcZ613ZrYxhRmF6:eGCSs0FbtuVRmF
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: fghj.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: fghj.exe

MSIL/Kryptik.AYC also known as:

K7AntiVirusTrojan ( 004b4ff51 )
LionicTrojan.Win32.Inject.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject.54651
MicroWorld-eScanGen:Variant.MSILKrypt.6
ALYacGen:Variant.MSILKrypt.6
CylanceUnsafe
ZillyaTrojan.Inject.Win32.31699
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Inject.323669d0
K7GWTrojan ( 004b4ff51 )
Cybereasonmalicious.bb9c47
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AYC
APEXMalicious
AvastMSIL:Agent-FI [Trj]
ClamAVWin.Dropper.Vobfus-9836928-0
KasperskyTrojan.Win32.Inject.cuxl
BitDefenderGen:Variant.MSILKrypt.6
NANO-AntivirusTrojan.Win32.Win32.dkfyhb
TencentWin32.Trojan.Inject.Suxl
Ad-AwareGen:Variant.MSILKrypt.6
SophosMal/Generic-S
ComodoMalware@#1f2xzpllk67lc
BitDefenderThetaGen:NN.ZemsilF.34266.Fm0@aSYnJ8b
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.51a1593bb9c47923
EmsisoftGen:Variant.MSILKrypt.6 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Inject.xcl
WebrootW32.Malware.Heur
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2C862E2
KingsoftWin32.Troj.Inject.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.MSILKrypt.6
AhnLab-V3Trojan/Win32.RL_Gen.C4009480
Acronissuspicious
McAfeeArtemis!51A1593BB9C4
MAXmalware (ai score=100)
VBA32Trojan.Inject
MalwarebytesMachineLearning/Anomalous.100%
YandexTrojan.Inject!VwiJHo2DrhI
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Inject.CUXL!tr
AVGMSIL:Agent-FI [Trj]
PandaGeneric Malware

How to remove MSIL/Kryptik.AYC?

MSIL/Kryptik.AYC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment