Malware

How to remove “MSIL/Kryptik.QAT”?

Malware Removal

The MSIL/Kryptik.QAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.QAT virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine MSIL/Kryptik.QAT?


File Info:

crc32: 36FDB102
md5: 0c6abe7e24590ed61d3a9fe967935f1a
name: 0C6ABE7E24590ED61D3A9FE967935F1A.mlw
sha1: 23bfbe548dbcc7e6166a0d0619b741eac51a372f
sha256: d864c49598d78028ebcc37f74b3b64221076162ba3ee0a6e81e579153d9628a7
sha512: c201a729602a5c45996a668897e2099a598609af2872d9ee22e0122cb11ac31531a2d30f6684f7bcff6b0422f2bd5528f0cffd046a1ec4b4a64d4ae7136f85a3
ssdeep: 12288:uCmm4KnZpRV27A3mx7ZKAEQsrP/414cnB8HfgKc65KuxdbipI73w30JKy6I0PY3:uVonFI7A3mxW/41tBEfgS5Kuxlia
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Crypted.exe
FileVersion: 1.0.0
CompanyName: Ki
Comments: ConfuserEx
ProductName: ConfuserEx
ProductVersion: 1.0.0
FileDescription: ConfuserEx GUI
OriginalFilename: Crypted.exe

MSIL/Kryptik.QAT also known as:

K7AntiVirusTrojan ( 005500731 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.117713
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 005500731 )
Cybereasonmalicious.e24590
CyrenW32/Trojan.BVR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.QAT
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Ursu-7748951-0
KasperskyHEUR:Trojan-Dropper.MSIL.Generic
BitDefenderGen:Variant.Bulz.117713
MicroWorld-eScanGen:Variant.Bulz.117713
TencentMsil.Trojan-dropper.Generic.Gvq
Ad-AwareGen:Variant.Bulz.117713
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34678.Qu0@a43Gske
TrendMicroTrojan.Win32.Boilod.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Packed.jc
FireEyeGeneric.mg.0c6abe7e24590ed6
EmsisoftGen:Variant.Bulz.117713 (B)
SentinelOneStatic AI – Malicious PE
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1101679
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftTrojan.Win32.Packed.vb!n
ArcabitTrojan.Bulz.D1CBD1
GDataGen:Variant.Bulz.117713
AhnLab-V3Trojan/Win32.Bladabindi.C2620000
Acronissuspicious
McAfeeArtemis!0C6ABE7E2459
MAXmalware (ai score=85)
VBA32CIL.StupidPInvoker-1.Heur
MalwarebytesTrojan.PasswordStealer
TrendMicro-HouseCallTrojan.Win32.Boilod.SM.hp
IkarusTrojan.MSIL.Confuser
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.QAT!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HwMAmkQA

How to remove MSIL/Kryptik.QAT?

MSIL/Kryptik.QAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment