Malware

Should I remove “MSIL/Kryptik.ZCT”?

Malware Removal

The MSIL/Kryptik.ZCT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZCT virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Kryptik.ZCT?


File Info:

name: D6DE8989D814C426A670.mlw
path: /opt/CAPEv2/storage/binaries/6d0c8312bead6e8831d361ba8145193c7615e9f104708a9644a4b5fcd535ad9a
crc32: 0821DD0D
md5: d6de8989d814c426a67033aef5397c08
sha1: f6aa0609dd08aedd09bdba2a9118e52b71a4f51b
sha256: 6d0c8312bead6e8831d361ba8145193c7615e9f104708a9644a4b5fcd535ad9a
sha512: c82dccbc7c5887880b79c0d396811105f95d1fc9ac779dfa671dda210499369d8ce98c6612904cc09c69bfee7a24243ebccc9c32c3b5f4b89764c33fb01a3c7b
ssdeep: 24576:nIkxianUA5sAJkgOS4A/vL4JGXuTUIhjPTG:njfUAWWBDUkuTUIhjPa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A25BE311FA6E934FC775B70C664B899AAAFFED26B33981D190035E50B3374D89E0429
sha3_384: 9b0907c28931d71b926f062d68af7f2bb5fd1f70c07caeacfeca91264fb10ed233f00b286e4be16f24ab741fb074413e
ep_bytes: ff250020400000000000000000000000
timestamp: 2064-09-13 01:01:35

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: CarInventory
FileVersion: 1.0.0.0
InternalName: ThreadPool.exe
LegalCopyright: Copyright © 2019
LegalTrademarks:
OriginalFilename: ThreadPool.exe
ProductName: CarInventory
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.ZCT also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.MSIL.Bsymem.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Olock.1
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
SkyhighAgentTesla-FCTY!D6DE8989D814
McAfeeAgentTesla-FCTY!D6DE8989D814
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Kryptik.Win32.2735376
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:MSIL/AgentTesla.852e67f4
K7GWTrojan ( 700000121 )
Cybereasonmalicious.9dd08a
BitDefenderThetaGen:NN.ZemsilF.36744.7m0@aOxk!Bp
VirITTrojan.Win32.MSIL_Heur.A
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Kryptik.ZCT
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Bsymem.gen
BitDefenderGen:Trojan.Olock.1
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan.Bsymem.Ekjl
EmsisoftTrojan.Crypt (A)
F-SecureTrojan.TR/Dropper.MSIL.Gen
VIPREGen:Trojan.Olock.1
FireEyeGeneric.mg.d6de8989d814c426
SophosTroj/Krypt-ABH
SentinelOneStatic AI – Suspicious PE
GDataGen:Trojan.Olock.1
JiangminTrojan.MSIL.toit
VaristW32/MSIL_Kryptik.CKT.gen!Eldorado
AviraTR/Dropper.MSIL.Gen
Kingsoftmalware.kb.c.844
XcitiumMalware@#2h1fq4i0nj6w7
ArcabitTrojan.Olock.1
ZoneAlarmHEUR:Trojan.MSIL.Bsymem.gen
MicrosoftTrojan:MSIL/AgentTesla.BHT!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.MSILKrypt.R357703
VBA32Malware-Cryptor.MSIL.AgentTesla.Heur
ALYacGen:Trojan.Olock.1
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:+vXoo4mt93jbJmXetyXs1A)
IkarusTrojan.Inject
MaxSecureTrojan.Malware.73722379.susgen
FortinetMSIL/GenKryptik.EYUG!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Kryptik.ZCT?

MSIL/Kryptik.ZCT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment