Malware

MSIL/Kryptik.QDX information

Malware Removal

The MSIL/Kryptik.QDX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.QDX virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.

Related domains:

z.whorecord.xyz
a.tomx.xyz
haso.ddns.net

How to determine MSIL/Kryptik.QDX?


File Info:

crc32: A06710B6
md5: e568762f4d127e0d7b610b08ffde2706
name: E568762F4D127E0D7B610B08FFDE2706.mlw
sha1: f51f231a2c8e92277e6757caa71cef7b0b58b739
sha256: a65bb6325027d0f814533adf8d7a907253a4327c007c7e2b844b8f60513ce8a7
sha512: cf935b554a1b3a74ba801519fc51f109ed3ceb0204ed9c13026182a6cacae7ddc3d8deee30a5232b9f6230761fd01f21521035712b138f47826cdfd4c305a5e5
ssdeep: 12288:UjIjTa3T45+c+qKIFSvqPX96FW0bHpHTqlVUWCshwgC2gS85r:nmk+c6IFSvqv9cWsHtq4WCshe2qr
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2008
Assembly Version: 63.56.57.11
InternalName: alibaba40.EXE
FileVersion: 63.84.72.55
Comments: WindowsApplication36
ProductName: WindowsApplication36
ProductVersion: 63.84.72.55
FileDescription: WindowsApplication36
OriginalFilename: alibaba40.EXE

MSIL/Kryptik.QDX also known as:

K7AntiVirusTrojan ( 0054111f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaDropper.Blocker.Win32.295
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Kryptik.2fd3a073
K7GWTrojan ( 0054111f1 )
Cybereasonmalicious.a2c8e9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.QDX
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
NANO-AntivirusTrojan.Win32.Ransom.fkicox
TencentWin32.Backdoor.Cybergate.Uijs
SophosMal/Generic-S
ComodoMalware@#11yi86oz1uqsb
BitDefenderThetaGen:NN.ZemsilF.34722.Mq0@aS3WoZf
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e568762f4d127e0d
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.296B35B
MicrosoftWorm:Win32/Rebhip
AegisLabTrojan.MSIL.Blocker.4!c
AhnLab-V3Trojan/Win32.Rebhip.C2880022
McAfeeArtemis!E568762F4D12
MAXmalware (ai score=100)
VBA32CIL.StupidPInvoker-2.Heur
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.QDX!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.QDX?

MSIL/Kryptik.QDX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment