Malware

MSIL/Kryptik.QEU malicious file

Malware Removal

The MSIL/Kryptik.QEU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.QEU virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.QEU?


File Info:

crc32: 8D1023C7
md5: 0fa04bdc432498291778f821ce47d724
name: 0FA04BDC432498291778F821CE47D724.mlw
sha1: b1eee50a481d45b023c3ff2caffd53ad234d0c3b
sha256: 1e1f34af00c7f0103a2de5c7363185f0453cbd9d83b709beb9da5d5d8eca662f
sha512: 73a60f5d4547e2df0563a630ad4d6572bcca2756d8df557987ab491192edd9e0b40f77090c24c29147294a91105bd01e7dd28f594e3ccdef263d221bc8c1d067
ssdeep: 24576:ImIeuF9yfi87syQi4psEaMdbQn0uO3nwxGutECjl5zbGBYiZa+w0LJAB18IM:ImdfiaQiSsE5dw0XUG8j/H2YzF0L4uT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: cosmic xa9 CentralSystem
Assembly Version: 30.18.15.12
InternalName: gateway.exe
FileVersion: 30.18.15.12
CompanyName: CentralSystem
ProductName: cosmic
ProductVersion: 30.18.15.12
FileDescription: CentralSystem
OriginalFilename: gateway.exe

MSIL/Kryptik.QEU also known as:

K7AntiVirusTrojan ( 0053e25b1 )
DrWebTrojan.MulDrop8.32421
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.40348765
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.143309
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Kryptik.8b6c35f9
K7GWTrojan ( 0053e25b1 )
Cybereasonmalicious.c43249
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.QEU
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.40348765
NANO-AntivirusTrojan.Win32.Generic.fgfkgk
MicroWorld-eScanTrojan.GenericKD.40348765
TencentMalware.Win32.Gencirc.114d46b8
Ad-AwareTrojan.GenericKD.40348765
SophosMal/Generic-S
ComodoMalware@#2zan8zhigmxr9
BitDefenderThetaGen:NN.ZemsilF.34266.qr2@aOCAcRg
McAfee-GW-EditionArtemis!Virus
FireEyeGeneric.mg.0fa04bdc43249829
EmsisoftTrojan.GenericKD.40348765 (B)
JiangminTrojan.MSIL.jxao
AviraHEUR/AGEN.1105318
eGambitPE.Heur.InvalidSig
Antiy-AVLTrojan/Generic.ASMalwS.271E36F
MicrosoftTrojan:Win32/Occamy.C1E
GDataTrojan.GenericKD.40348765
AhnLab-V3Trojan/Win32.AutoRun.C2639070
McAfeeArtemis!0FA04BDC4324
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
YandexTrojan.Agent!Estpuy+7Oag
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.QEU?

MSIL/Kryptik.QEU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment