Malware

MSIL/Kryptik.ZCO removal

Malware Removal

The MSIL/Kryptik.ZCO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZCO virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ZCO?


File Info:

crc32: B1C70AD9
md5: 7b80992176d91fe6ccb5301fb16e3e40
name: 7B80992176D91FE6CCB5301FB16E3E40.mlw
sha1: 77bee4b3b07c367f45ea8ecd87eb65b317900fd9
sha256: 641a1d0d54fc5d0facf1c2c20d1cb54f60705d67b5990b3be3cfcb7e8c1269a4
sha512: 154b6a62df5c058c49ad58ddf0fefedb7675c9e8c06f5a637fd50d9869409772c954271de6f4791b774eb921030afc4d40e50f1523194c86b1c6e795aca258fd
ssdeep: 12288:nsTC6rj7kxWfnUpcWcyCFKL+92Gh0xd87:MC6r8wPUOWy0L+v7
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1997 9H<==B<HJ4I83H7H9
Assembly Version: 1.0.0.0
InternalName: QP-10533.exe
FileVersion: 3.4.5.6
CompanyName: 9H<==B<HJ4I83H7H9
Comments: >3;7;AF4B=8IAJG56C>F@
ProductName: JH@=6JE;C@:9BE5FB<CD9
ProductVersion: 3.4.5.6
FileDescription: JH@=6JE;C@:9BE5FB<CD9
OriginalFilename: QP-10533.exe

MSIL/Kryptik.ZCO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35842073
FireEyeGeneric.mg.7b80992176d91fe6
Qihoo-360Generic/Backdoor.23a
ALYacTrojan.GenericKD.35842073
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderTrojan.GenericKD.35842073
K7GWTrojan ( 005751f41 )
K7AntiVirusTrojan ( 005751f41 )
CyrenW32/MSIL_Kryptik.AHY.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
AlibabaBackdoor:MSIL/Kryptik.9b1e6e90
ViRobotTrojan.Win32.Z.Agent.587640
Ad-AwareTrojan.GenericKD.35842073
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Kryptik.dbzea
DrWebTrojan.Inject4.6358
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
IkarusTrojan-Spy.Keylogger.AgentTesla
JiangminBackdoor.MSIL.ebty
WebrootW32.Trojan.Gen
AviraTR/Kryptik.dbzea
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA64
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D222E819
ZoneAlarmHEUR:Backdoor.MSIL.Remcos.gen
GDataTrojan.GenericKD.35842073
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Kryptik.R360201
McAfeeRDN/Generic PWS.y
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/Genetic.gen
ESET-NOD32a variant of MSIL/Kryptik.ZCO
TrendMicro-HouseCallTROJ_GEN.R002H0ALN20
RisingTrojan.Kryptik!8.8 (TFE:C:3zq9sF6LUCE)
FortinetMSIL/Kryptik.ZCO!tr
BitDefenderThetaGen:NN.ZemsilF.34700.Jm2@ayb61Fe
AVGWin32:Trojan-gen
Cybereasonmalicious.3b07c3
AvastWin32:Trojan-gen

How to remove MSIL/Kryptik.ZCO?

MSIL/Kryptik.ZCO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment