Malware

How to remove “MSIL/Kryptik.ZAI”?

Malware Removal

The MSIL/Kryptik.ZAI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZAI virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/Kryptik.ZAI?


File Info:

crc32: 03138074
md5: 0e1dbe1dfd3aad4027f0e3e857f7e701
name: 0E1DBE1DFD3AAD4027F0E3E857F7E701.mlw
sha1: f2e83d611d5d5b5cfdf9b76aa7d2446b53eb1542
sha256: bfdc30b761b68160744dfd8e664af2f198b945b497025b35129b7cde7efe230d
sha512: 0c7051ea3e4140548f53b5041e473270ff314bbaf72110099764eff78b23eea6a39dfb55af35da3ec61a0c249adecc37d209f236727b0f66b3b6f47bb2e980a0
ssdeep: 24576:JDKHFaaQWQmIc3fuF+/Ev1lWCFODy0svdmyYVaQIx9k:JWHFaaTf/cZI6dzQI
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Hewlett-Packard 2016
Assembly Version: 4.50.0.0
InternalName: LocalBuilder.exe
FileVersion: 4.50.0.0
CompanyName: Hewlett-Packard
LegalTrademarks:
Comments:
ProductName: Grocery Store Delivery
ProductVersion: 4.50.0.0
FileDescription: Grocery Store Delivery
OriginalFilename: LocalBuilder.exe

MSIL/Kryptik.ZAI also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44995994
FireEyeGeneric.mg.0e1dbe1dfd3aad40
McAfeeArtemis!0E1DBE1DFD3A
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 005749b71 )
BitDefenderTrojan.GenericKD.44995994
K7GWTrojan ( 005749b71 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Trojan.KOJV-2881
SymantecTrojan Horse
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.NetWiredRC.gen
AlibabaBackdoor:MSIL/NetWiredRC.3f273ebf
Ad-AwareTrojan.GenericKD.44995994
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.plyuc
DrWebTrojan.Packed2.42726
TrendMicroBackdoor.MSIL.NETWIRED.THLADBO
McAfee-GW-EditionBehavesLike.Win32.Packed.fc
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Malicious PE
AviraTR/Redcap.plyuc
MAXmalware (ai score=100)
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AABF
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2AE959A
ZoneAlarmHEUR:Backdoor.MSIL.NetWiredRC.gen
GDataTrojan.GenericKD.44995994
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4261762
BitDefenderThetaGen:NN.ZemsilF.34688.@u0@aS4Cmwh
ALYacBackdoor.RAT.Netwire
VBA32CIL.HeapOverride.Heur
ESET-NOD32a variant of MSIL/Kryptik.ZAI
TrendMicro-HouseCallBackdoor.MSIL.NETWIRED.THLADBO
YandexTrojan.AvsArher.bUx2VN
IkarusTrojan-Spy.Keylogger.AgentTesla
eGambitUnsafe.AI_Score_98%
FortinetW32/NetWiredRC!tr.bdr
WebrootW32.Trojan.Gen
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.11d5d5
AvastWin32:RATX-gen [Trj]
Qihoo-360Generic/Trojan.402

How to remove MSIL/Kryptik.ZAI?

MSIL/Kryptik.ZAI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment