Malware

About “MSIL/Kryptik.ZLE” infection

Malware Removal

The MSIL/Kryptik.ZLE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZLE virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ZLE?


File Info:

crc32: C539C76C
md5: 208f2494a82c3b830d676c187e1f03d1
name: 208F2494A82C3B830D676C187E1F03D1.mlw
sha1: 98f350298f0b61cfd94c73bca51ef61802188527
sha256: a659c50e03822cd595bf5d21007b2870fda97b6d4a5d3840d68bf8f333cc47ea
sha512: 46ba20d289b65037851c5658d29a5325d90f9ede1310756750428e54befe6f45c5169e31581560899bc9e1d7c90b066493d2d4e0d2bbaccaae56103437837d63
ssdeep: 12288:tcd3/l3lFULj81T1No2u2k8Iqpy5/N/MZBCs0vvG7PH71UF+Z:i9MLj8pLor2k8ISGVM2qqu
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: XmlToFieldTypeMap.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: BowenTheatre.Bookings
ProductVersion: 1.0.0.0
FileDescription: BowenTheatre.Bookings
OriginalFilename: XmlToFieldTypeMap.exe

MSIL/Kryptik.ZLE also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.471
McAfeePWS-FCUZ!208F2494A82C
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00576d7c1 )
BitDefenderTrojan.GenericKD.36254767
K7GWTrojan ( 00576d7c1 )
ArcabitTrojan.Generic.D229342F
CyrenW32/MSIL_Kryptik.CWT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ZLE
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
MicroWorld-eScanTrojan.GenericKD.36254767
Ad-AwareTrojan.GenericKD.36254767
EmsisoftTrojan.GenericKD.36254767 (B)
F-SecureTrojan.TR/AD.AgentTesla.twbdj
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.208f2494a82c3b83
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.AgentTesla.twbdj
MAXmalware (ai score=84)
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
AegisLabTrojan.MSIL.Agensla.i!c
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.36254767
ALYacTrojan.GenericKD.36254767
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00AR21
IkarusTrojan.MSIL.Inject
FortinetMSIL/Kryptik.ZKU!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]

How to remove MSIL/Kryptik.ZLE?

MSIL/Kryptik.ZLE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment