Ransom Trojan

Trojan-Ransom.MSIL.Cryakl information

Malware Removal

The Trojan-Ransom.MSIL.Cryakl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.MSIL.Cryakl virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.MSIL.Cryakl?


File Info:

crc32: 974EE5F7
md5: c905a7cf4166aba92e63e52d2e04329a
name: C905A7CF4166ABA92E63E52D2E04329A.mlw
sha1: 1773b8b45a00730ea20ee1519b20e7495ea6bb4c
sha256: a82789d3ec7dad550114bbf77e02ac5ec4b2ef1a314a92b48474ab053d6c6be7
sha512: e27364f19bc98d50bcf3917b0783f9f434e89c6b27fe99ab60444675bb01c1af34e6fcc75013e4ead9c0ec5592848b4ca0e4bb08d231a8e3cd3eb80c0470b421
ssdeep: 6144:5ivA9c0BcDo9I6mxWT+nBL3XVJO4Cu8xMJ7Q508r9upY60DdXkEjVT3Dn:kvA9Oo9I6mxe+ndO4aM80BW9uEjVP
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: 1.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: 1.exe

Trojan-Ransom.MSIL.Cryakl also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.6.Gen
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.44450
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.f4166a
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.NHT
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Cryakl.gen
BitDefenderTrojan.MSIL.Basic.6.Gen
NANO-AntivirusTrojan.Win32.Androm.eqrouu
MicroWorld-eScanTrojan.MSIL.Basic.6.Gen
TencentWin32.Trojan.Filecoder.Swuf
Ad-AwareTrojan.MSIL.Basic.6.Gen
SophosMal/Generic-S
ComodoMalware@#2e239cm2cq73q
BitDefenderThetaGen:NN.ZemsilF.34722.AmW@aStfW4h
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPICH.F117G7
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.c905a7cf4166aba9
EmsisoftTrojan.MSIL.Basic.6.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.qve
AviraHEUR/AGEN.1109314
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2109DC2
MicrosoftTrojan:Win32/Dynamer!rfn
ArcabitTrojan.MSIL.Basic.6.Gen
GDataTrojan.MSIL.Basic.6.Gen
AhnLab-V3Trojan/Win32.Androm.C2118963
Acronissuspicious
McAfeeArtemis!C905A7CF4166
MAXmalware (ai score=99)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPICH.F117G7
YandexBackdoor.Androm!Nid9fGeSZF0
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Androm.NHT!tr.bdr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.MSIL.Cryakl?

Trojan-Ransom.MSIL.Cryakl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment