Malware

About “MSIL/Kryptik.ZKY” infection

Malware Removal

The MSIL/Kryptik.ZKY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZKY virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ZKY?


File Info:

crc32: 5A4F6225
md5: e55410171f24865fcf6979d3cfee83a2
name: E55410171F24865FCF6979D3CFEE83A2.mlw
sha1: 6ea3a9652822aae16af97605e98f031e8be97e31
sha256: eb32326655d9ff8ffab963e29d0000703da122353d65091f4f56ab252e45299a
sha512: d68ffea38f152a6032bbd269b43c3cb9113292618e78317f90b9496228750c6ec9363fac94b7011e424ca7f485cc7d9a01e2c3ad0d150f476c3c11be9a51cf20
ssdeep: 12288:TYmF18qpWAxYV7bYWruDR3WXvP58S42sqfO:TbuYWwGbyR3WXHaS4aO
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: PublisherIdentityPermissionAttribute.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: broke-mobile
ProductVersion: 1.0.0.0
FileDescription: broke-mobile
OriginalFilename: PublisherIdentityPermissionAttribute.exe

MSIL/Kryptik.ZKY also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72696
FireEyeGeneric.mg.e55410171f24865f
McAfeeGenericRXNL-NZ!E55410171F24
CylanceUnsafe
AegisLabTrojan.Win32.Generic.lUy1
BitDefenderTrojan.GenericKDZ.72696
Cybereasonmalicious.71f248
CyrenW32/MSIL_Kryptik.CWC.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKDZ.72696
SophosMal/Generic-S + Troj/MSIL-QMA
ComodoTrojWare.Win32.Genome.kwbne@0
DrWebTrojan.PackedNET.471
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKDZ.72696 (B)
IkarusTrojan.MSIL.Inject
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D11BF8
GDataTrojan.GenericKDZ.72696
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R364274
BitDefenderThetaGen:NN.ZemsilF.34780.Hm0@am71LJm
ALYacGen:Variant.Strictor.94570
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of MSIL/Kryptik.ZKY
TrendMicro-HouseCallTROJ_GEN.R06CH09AQ21
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.ZKP!tr
AVGWin32:PWSX-gen [Trj]

How to remove MSIL/Kryptik.ZKY?

MSIL/Kryptik.ZKY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment