Ransom

How to remove “Ransom:MSIL/Chalkrypt.A”?

Malware Removal

The Ransom:MSIL/Chalkrypt.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MSIL/Chalkrypt.A virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ransom:MSIL/Chalkrypt.A?


File Info:

crc32: 6AFCD440
md5: b86e5f581acbdb37e2aa79675f0fe30f
name: B86E5F581ACBDB37E2AA79675F0FE30F.mlw
sha1: 48c58edc7c1fe09207c13a687b393bd57351f46c
sha256: 4f486bf367535aa60a223d9083db6ec93442e3ab7553b7ab39f16f89df30a828
sha512: 050e07220a1e59e72330eba7ae928ea91b5ef14585d39b347b13edf3968c01414d572ac51567850c4b119745d137119f31919e4053405e849736947848ea7785
ssdeep: 3072:gX3shfByD3/G5Y2R/hXHNfiCaBiTe0La0/ybDm5mgo0rhyP5:gzUhdhaETe0W0/ybDbgw
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.7.0.0
InternalName: EGG.exe
FileVersion: 1.7.2.0
CompanyName: :^)
LegalTrademarks:
Comments: FREEWARE
ProductName: WindowsFormsApp1
ProductVersion: 1.7.2.0
FileDescription: WindowsFormsApp1
OriginalFilename: EGG.exe

Ransom:MSIL/Chalkrypt.A also known as:

MicroWorld-eScanGen:Variant.Ursu.135056
FireEyeGen:Variant.Ursu.135056
McAfeeGenericRXEK-CI!B86E5F581ACB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0050fe0b1 )
BitDefenderGen:Variant.Ursu.135056
K7GWTrojan ( 0050fe0b1 )
BitDefenderThetaGen:NN.ZemsilF.34590.Dm0@aif8Fqp
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
RisingTrojan.Filecoder!8.68 (CLOUD)
Ad-AwareGen:Variant.Ursu.135056
SophosMal/Generic-S
TrendMicroRansom_GEGLOCKER.SMALY
McAfee-GW-EditionGenericRXEK-CI!B86E5F581ACB
EmsisoftGen:Variant.Ursu.135056 (B)
MAXmalware (ai score=82)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:MSIL/Chalkrypt.A
ArcabitTrojan.Ursu.D20F90
GDataGen:Variant.Ursu.135056
AhnLab-V3Trojan/Win32.FileCoder.C2445851
ALYacGen:Variant.Ursu.135056
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Filecoder.GP
TrendMicro-HouseCallRansom_GEGLOCKER.SMALY
TencentWin32.Trojan.Razy.Pfte
YandexTrojan.Filecoder!cdR7jVp3XHE
FortinetMSIL/Filecoder.GP!tr.ransom
AVGWin32:Malware-gen
Cybereasonmalicious.81acbd
Qihoo-360Win32/Trojan.Generic.HgIASOoA

How to remove Ransom:MSIL/Chalkrypt.A?

Ransom:MSIL/Chalkrypt.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment