Malware

Should I remove “MSIL/Kryptik.ZKV”?

Malware Removal

The MSIL/Kryptik.ZKV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZKV virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ZKV?


File Info:

crc32: 0FF29328
md5: 5391ce0f54de6dbc9be26c5fada0f2f4
name: 5391CE0F54DE6DBC9BE26C5FADA0F2F4.mlw
sha1: 134710137d1d9dec503aba0f74ad2154092a04c4
sha256: 3e784435800339cfeb624d5f09e5d5adc54ddad251eaadcab47cdeeb510b0259
sha512: 543aa1609a55e24d6c66d43cd98ffe503c2c7e1cd0f0297c8f760107404cc5804565f4beb0b5ca6cb883ab6bda9022de10878ea983770cce4d481d1ab298b524
ssdeep: 6144:5P8pUOVtLVD7KaxvKAho4ThzSTodJf37oJpt9fcTgqrY:mVtLVD7Kaxvto4ThzSToddoZtcjY
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014 - 2020
Assembly Version: 1.0.0.0
InternalName: JL.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Kids vs IceCream
ProductVersion: 1.0.0.0
FileDescription: Kids vs IceCream
OriginalFilename: JL.exe

MSIL/Kryptik.ZKV also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.SpyBotNET.25
MicroWorld-eScanTrojan.GenericKD.36244450
FireEyeGeneric.mg.5391ce0f54de6dbc
McAfeePWS-FCQR!5391CE0F54DE
CylanceUnsafe
AegisLabTrojan.MSIL.Agensla.i!c
K7AntiVirusTrojan ( 00576bb61 )
BitDefenderTrojan.GenericKD.36244450
K7GWTrojan ( 00576bb61 )
BitDefenderThetaGen:NN.ZemsilCO.34780.ym0@a4EzoSk
CyrenW32/MSIL_Agent.BSK.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
ViRobotTrojan.Win32.Z.Kryptik.395776.DV
TencentWin32.Trojan.Inject.Auto
Ad-AwareTrojan.GenericKD.36244450
SophosMal/Generic-R + Troj/Kryptik-QZ
ComodoMalware@#gt3t9cf3l90i
TrendMicroTROJ_FRS.0NA103AQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
EmsisoftTrojan.GenericKD.36244450 (B)
IkarusTrojan.MSIL.Crypt
AviraTR/Kryptik.nebju
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AA3E
ArcabitTrojan.Generic.D2290BE2
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.36244450
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4310048
ALYacSpyware.Infostealer.Azorult
MAXmalware (ai score=99)
MalwarebytesGeneric.Malware/Suspicious
ESET-NOD32a variant of MSIL/Kryptik.ZKV
TrendMicro-HouseCallTROJ_FRS.0NA103AQ21
SentinelOneStatic AI – Malicious PE
FortinetMSIL/GenKryptik.FAMC!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.PSW.374

How to remove MSIL/Kryptik.ZKV?

MSIL/Kryptik.ZKV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment