Malware

MSIL/Kryptik.ZIH removal guide

Malware Removal

The MSIL/Kryptik.ZIH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZIH virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ZIH?


File Info:

crc32: 62584A07
md5: c6091ddf2745b7edcfa535d727ea7b7a
name: C6091DDF2745B7EDCFA535D727EA7B7A.mlw
sha1: 769608c06ff9bd184be238b6c92769533eaef750
sha256: 1c92e75853c17bb45af6a066b89e395f3e0d1cb07f2f0b1bc61d2e069bba29ae
sha512: 9c49f8df4e609552f88f3af71a96ed8829f067b556b02f207165bbe1226350883d690d09af18356eba37973d4a195a98f9741479b90958b971af819351061d75
ssdeep: 24576:t6ZO8rKp6dJxTvuNRrER+CJW72LmCdnx4boIaA:t648rtdJxTAM+qW72LhvIx
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017 Natural
Assembly Version: 199.8.0.0
InternalName: ControllerCommand.exe
FileVersion: 199.8.0.0
CompanyName: Trilogy International Limited
LegalTrademarks:
Comments: Trilogy Natural Products
ProductName: CS Natural
ProductVersion: 199.8.0.0
FileDescription: CS Natural
OriginalFilename: ControllerCommand.exe

MSIL/Kryptik.ZIH also known as:

MicroWorld-eScanTrojan.GenericKD.36161531
Qihoo-360Win32/Trojan.PWS.d75
McAfeeGenericRXNK-DB!C6091DDF2745
AegisLabTrojan.MSIL.Crypt.4!c
SangforMalware
K7AntiVirusTrojan ( 005765d21 )
BitDefenderTrojan.GenericKD.36161531
K7GWTrojan ( 005765d21 )
ArcabitTrojan.Generic.D227C7FB
CyrenW32/MSIL_Kryptik.CSG.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ZIH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaTrojan:MSIL/AgentTesla.8455a299
Ad-AwareTrojan.GenericKD.36161531
SophosTroj/Kryptik-QO
ComodoMalware@#3e033ngposg3e
F-SecureTrojan.TR/Kryptik.jzyoa
DrWebTrojan.PackedNET.511
TrendMicroTrojanSpy.MSIL.LOKI.CLPB
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36161531
EmsisoftTrojan.GenericKD.36161531 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.jzyoa
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:MSIL/AgentTesla.AM!MTB
AhnLab-V3Trojan/Win32.Kryptik.R363509
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
GDataWin32.Trojan-Stealer.LokiBot.4I32HS
CynetMalicious (score: 90)
ALYacTrojan.GenericKD.36161531
MAXmalware (ai score=99)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.LOKI.CLPB
TencentMsil.Trojan.Crypt.Svqv
IkarusTrojan.MSIL.Inject
FortinetMSIL/Kryptik.ZGP!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove MSIL/Kryptik.ZIH?

MSIL/Kryptik.ZIH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment