Malware

What is “MSIL/Kryptik.NEA”?

Malware Removal

The MSIL/Kryptik.NEA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.NEA virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.NEA?


File Info:

crc32: C3538C99
md5: 45b21e78830c86d206239aead650dce8
name: 45B21E78830C86D206239AEAD650DCE8.mlw
sha1: 7f7df4afc7d85299845e72ad6b03621399988055
sha256: 5f30fd7b783aecda537d538ebe8ba6ee30384bd0e4b8477a88305843f4f26c23
sha512: da7f42cedfaae0d738b445d4329806b53d543563382bec49bfb0151b7fc0283e6c9481d9423bae2f3936dc9798f6ac0a4b22093ac7bcabc8c51825db88000eec
ssdeep: 384:MzQBWU9mHd/N2oFmydpOp7Kdw+NPbaC0IDrLWBC0W:MsC/I0pOgdxbaC0I33
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: WUDFHost.exe
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.14393.0
FileDescription: Windows Driver Foundation - User-mode Driver Framework Host Process
OriginalFilename: WUDFHost.exe
Translation: 0x0409 0x04b0

MSIL/Kryptik.NEA also known as:

K7AntiVirusTrojan ( 005131db1 )
LionicTrojan.Win32.Generic.4!c
ALYacIL:Trojan.MSILZilla.7001
CylanceUnsafe
SangforTrojan.Win32.Generic.8
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.89fb452f
K7GWTrojan ( 005131db1 )
Cybereasonmalicious.8830c8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.NEA
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Malwarex-6866182-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderIL:Trojan.MSILZilla.7001
NANO-AntivirusTrojan.Win32.Mlw.erutds
MicroWorld-eScanIL:Trojan.MSILZilla.7001
TencentWin32.Trojan.Dropper.Pdwc
Ad-AwareIL:Trojan.MSILZilla.7001
SophosMal/Generic-S
ComodoTrojWare.MSIL.Kryptik.NE@81eks7
BitDefenderThetaGen:NN.ZemsilF.34266.am1@ammCD7pi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GKE21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.45b21e78830c86d2
EmsisoftIL:Trojan.MSILZilla.7001 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_91%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataIL:Trojan.MSILZilla.7001
McAfeeArtemis!45B21E78830C
MAXmalware (ai score=100)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0GKE21
IkarusTrojan.MSIL.Injector
FortinetMSIL/Kryptik.NEA!tr
AVGWin32:Malware-gen

How to remove MSIL/Kryptik.NEA?

MSIL/Kryptik.NEA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment