Malware

MSIL/Kryptik.ZAV information

Malware Removal

The MSIL/Kryptik.ZAV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZAV virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ZAV?


File Info:

crc32: 5BAFA0F0
md5: d543a59ba12985acaf4134c3ff427b86
name: D543A59BA12985ACAF4134C3FF427B86.mlw
sha1: 626f4d2877429d63586bc0ccfdf313911b6817c8
sha256: 45758c4c53cd20b6f598a9cba7185150543d829eee00aaa8dc565cefd59e9909
sha512: 80bfd4931b4a0e032fd583544cdf4fe36a0791d988b3ccfdcffe826fb1f93dabadf9de7f0a309da5eca1972839420e0c4bac796b9768d740075980459962689e
ssdeep: 24576:CFTW2xvuYI5n5LMjmMtKgEllwGyiMUUdXNX7XyPaaXBn7zF2lTnoO44vL/BjfPz:KTW2xvuYI55LMjmMtKgEllwGyiMUUxN
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Sinopharm-Beijing 2020 (C)
Assembly Version: 1.0.88.8
InternalName: BaseChannelWithProperties.exe
FileVersion: 1.0.88.8
CompanyName: Sinopharm-Beijing
LegalTrademarks:
Comments: CanSino Biologics
ProductName: Entrance Exam
ProductVersion: 1.0.88.8
FileDescription: Entrance Exam
OriginalFilename: BaseChannelWithProperties.exe

MSIL/Kryptik.ZAV also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45016395
FireEyeGeneric.mg.d543a59ba12985ac
ALYacBackdoor.RAT.Netwire
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0056de511 )
BitDefenderTrojan.GenericKD.45016395
K7GWTrojan ( 0056de511 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZemsilF.34700.2m0@aOB2yb
CyrenW32/MSIL_Kryptik.CLL.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Taskun.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
ViRobotTrojan.Win32.Z.Wacatac.887296
Ad-AwareTrojan.GenericKD.45016395
EmsisoftTrojan.Crypt (A)
DrWebTrojan.Packed2.42726
McAfee-GW-EditionRDN/Generic.dx
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
MAXmalware (ai score=85)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA2A
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2AEE54B
ZoneAlarmHEUR:Trojan.MSIL.Taskun.gen
GDataTrojan.GenericKD.45016395
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.C4263004
McAfeeRDN/Generic.dx
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.ZAV
YandexTrojan.Taskun!Z/c0yEf9Gw4
IkarusTrojan.MSIL.Inject
FortinetMSIL/GenKryptik.ERVS!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.877429
AvastWin32:RATX-gen [Trj]
Qihoo-360Generic/Trojan.477

How to remove MSIL/Kryptik.ZAV?

MSIL/Kryptik.ZAV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment