Malware

MSIL/Kryptik.QAJ removal tips

Malware Removal

The MSIL/Kryptik.QAJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.QAJ virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.QAJ?


File Info:

crc32: 4DED5AD6
md5: d6907f07202f475737f4da839b6b3aa1
name: D6907F07202F475737F4DA839B6B3AA1.mlw
sha1: ed513295c12df5891155f39bea2f2ff87a1d417e
sha256: c87136a79cb4d2215ebdae6fa7b32beb6d05466d7091a0181c599b8e73e1469b
sha512: 6fc18ddb815a03f33eb5e810ebc53a82a49f4b754ebacbf9979a7e763346f802ae0de7e55983c4dd3347fb6aa336b80d0912ac5577f92e7d0bfd602b049684c5
ssdeep: 12288:tzNxLiuMPrWnaQSCfJQMCaXm7oDhnGHekS989EG4S:/xLiHKiQJQrgpwH7P2G4S
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018 Archer Daniels Midland Company
Assembly Version: 0.0.0.0
InternalName: Gosp.exe
FileVersion: 10.8.14.1
CompanyName: StanMat
Comments: StanMat
ProductName: StanMat
ProductVersion: 10.8.14.1
FileDescription: StanMat
OriginalFilename: Gosp.exe

MSIL/Kryptik.QAJ also known as:

K7AntiVirusTrojan ( 005402281 )
LionicTrojan.MSIL.Crypmod.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.MSIL.Basic.1.Gen
CylanceUnsafe
ZillyaTrojan.Crypmod.Win32.765
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:MSIL/Crypmod.bf1e42e5
K7GWTrojan ( 005402281 )
Cybereasonmalicious.7202f4
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.QAJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Crypmod.gen
BitDefenderTrojan.MSIL.Basic.1.Gen
NANO-AntivirusTrojan.Win32.Ransom.iluulj
MicroWorld-eScanTrojan.MSIL.Basic.1.Gen
TencentMsil.Trojan.Crypmod.Wrzs
Ad-AwareTrojan.MSIL.Basic.1.Gen
SophosMal/Generic-S
ComodoMalware@#33ex51o547bi8
BitDefenderThetaGen:NN.ZemsilF.34088.Km0@aSv60@
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.hc
FireEyeGeneric.mg.d6907f07202f4757
EmsisoftTrojan.MSIL.Basic.1.Gen (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.knqa
AviraHEUR/AGEN.1118530
eGambitUnsafe.AI_Score_85%
Antiy-AVLTrojan/Generic.ASMalwS.2994C45
MicrosoftTrojan:Win32/Tnega!ml
ArcabitTrojan.MSIL.Basic.1.Gen
GDataTrojan.MSIL.Basic.1.Gen
AhnLab-V3Trojan/Win.MSIL.C4515165
Acronissuspicious
McAfeeArtemis!D6907F07202F
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.73703920.susgen
FortinetMSIL/GandCrab.FOD!tr.ransom
AVGWin32:Malware-gen

How to remove MSIL/Kryptik.QAJ?

MSIL/Kryptik.QAJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment