Malware

How to remove “MSIL/Kryptik.ZPI”?

Malware Removal

The MSIL/Kryptik.ZPI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZPI virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ZPI?


File Info:

crc32: 59420F63
md5: 7d02126353a885657e4553d365b0bbb0
name: 7D02126353A885657E4553D365B0BBB0.mlw
sha1: a63c25a69044c0694589578c9aa4710a2280f77b
sha256: ecb4381261e27c08650665f096f4873fd07a1466ae08149e6afc33af2a1ed1f8
sha512: 43a9f8f691ae375d38335f6563f1e5e5664ffb6fd8e855e1dbdfd05641f4a03c3ed1c90e2ee80781f96c86015417ea5ba37b6bae84d0300efabaa8f0089fdca3
ssdeep: 6144:4a62ScjLZ8eg16RnRIEIL+17ywkpH2R5kJNbbZ1KteFN7QH0A4MGdROS/GEAugG:
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: .NET Serialization Assembly Generator
FileVersion: 1.0.24211.07 built by: PROJECTNSVC2
CompanyName: Microsoft Corporation
ProductName: Microsoftxae .NET Framework
ProductVersion: 1.0.24211.07 built by: PROJECTNSVC2
FileDescription: .NET Serialization Assembly Generator
OriginalFilename: .NET Serialization Assembly Generator
Translation: 0x0409 0x04e4

MSIL/Kryptik.ZPI also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.536
MicroWorld-eScanTrojan.GenericKD.45699866
McAfeeArtemis!7D02126353A8
CylanceUnsafe
AegisLabTrojan.MSIL.Agensla.i!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005777ee1 )
BitDefenderTrojan.GenericKD.45699866
K7GWTrojan ( 005777ee1 )
BitDefenderThetaGen:NN.ZemsilF.34804.Yn0@aa8lc4ji
CyrenW32/MSIL_Kryptik.CYI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/AgentTesla.6dea38c2
RisingBackdoor.Nanocore!8.F894 (CLOUD)
Ad-AwareTrojan.GenericKD.45699866
EmsisoftTrojan.Crypt (A)
ComodoMalware@#2nyidwjz77nfu
F-SecureTrojan.TR/Kryptik.egydn
TrendMicroTrojanSpy.MSIL.NEGASTEAL.THBOHBA
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.45699866
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.bfzt
MaxSecureTrojan.Malware.74499699.susgen
AviraTR/Kryptik.egydn
MAXmalware (ai score=99)
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.AM!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B9531A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.45699866
CynetMalicious (score: 100)
ALYacBackdoor.RAT.MSIL.NanoCore
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.ZPI
TrendMicro-HouseCallTrojanSpy.MSIL.NEGASTEAL.THBOHBA
TencentWin32.Trojan.Inject.Auto
IkarusTrojan.MSIL.Krypt
eGambitUnsafe.AI_Score_95%
FortinetMSIL/GenKryptik.FBHJ!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Kryptik.HgIASOoA

How to remove MSIL/Kryptik.ZPI?

MSIL/Kryptik.ZPI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment