Malware

MSILKrypt.4 (B) removal instruction

Malware Removal

The MSILKrypt.4 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILKrypt.4 (B) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSILKrypt.4 (B)?


File Info:

crc32: 0C1B467A
md5: a9c05b72c5378c9533a0d7426ae1fcc6
name: A9C05B72C5378C9533A0D7426AE1FCC6.mlw
sha1: 521e73dd870ddc1433e8883a0e22cf289835cdd8
sha256: e2220683cd3dd158350e719784e791e91af479433906c4fab93513dfb1113865
sha512: d81fc0008d93125accaee42cf21666d0556617563582086d03ee1859bf4051bea3d117e7a6d64b9f50b728a2a6156af2b87f610af745b7a903f652c23626e671
ssdeep: 192:kbiZs1n/Bpug/GIofHqezZzI93VQUmrdsTRC:L8/BpvkHqeCFQUmZst
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: feTmnNjWZdpy
Assembly Version: 1.0.0.0
InternalName: Hackamores.exe
FileVersion: 1.0.0.0
CompanyName: XelommLJPUxVGj
LegalTrademarks: HwgJilCLtR
Comments: AlXAviMWtLNK
ProductName: EYNBkeUIauQpywJbrpl
ProductVersion: 1.0.0.0
FileDescription: uNKCWqVoVjNXXHAW
OriginalFilename: Hackamores.exe

MSILKrypt.4 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILKrypt.4
FireEyeGen:Variant.MSILKrypt.4
CAT-QuickHealTrojandownloader.Smallagent
ALYacGen:Variant.MSILKrypt.4
CylanceUnsafe
K7AntiVirusTrojan ( 0056d54c1 )
BitDefenderGen:Variant.MSILKrypt.4
K7GWTrojan ( 0056d54c1 )
Cybereasonmalicious.2c5378
TrendMicroTrojan.MSIL.USICE.SMJCDP
CyrenW32/Trojan.FOP.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Agent.gen
AlibabaTrojanDownloader:MSIL/SmallAgent.0bb9487e
NANO-AntivirusTrojan.Win32.Razy.htrpkt
AegisLabTrojan.Win32.Generic.4!c
TencentMsil.Trojan.Agent.Lpky
Ad-AwareGen:Variant.MSILKrypt.4
F-SecureHeuristic.HEUR/AGEN.1138839
DrWebTrojan.DownLoader34.20342
VIPRETrojan.Win32.Generic!BT
InvinceaTroj/MSIL-PNC
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
EmsisoftGen:Variant.MSILKrypt.4 (B)
AviraHEUR/AGEN.1138839
Antiy-AVLGrayWare/Win32.Agent.bkt
MicrosoftTrojanDownloader:MSIL/SmallAgent.SBR!MSR
GridinsoftTrojan.Win32.Agent.oa
ArcabitTrojan.MSILKrypt.4
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataMSIL.Trojan.SmallAgent.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Krypt.R347301
McAfeeGenericRXLS-VU!A9C05B72C537
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.BlackSpider
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.TZL
TrendMicro-HouseCallTrojan.MSIL.USICE.SMJCDP
RisingTrojan.MSIL/Agent!1.CF2E (CLASSIC)
IkarusTrojan.MSIL.Agent
FortinetMSIL/Razy.7018!tr
BitDefenderThetaGen:NN.ZemsilF.34634.am0@a4x7lii
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.fc8

How to remove MSILKrypt.4 (B)?

MSILKrypt.4 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment