Malware

MSIL/Kryptik.QPE (file analysis)

Malware Removal

The MSIL/Kryptik.QPE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.QPE virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.QPE?


File Info:

name: 659CBCC428A122B47658.mlw
path: /opt/CAPEv2/storage/binaries/812557c2aa0d39df9ba8e8c5f2ca460581fbe945925e41cc6eef541b60000da6
crc32: 2C5B2806
md5: 659cbcc428a122b47658ca81df6fad77
sha1: 1dc553a58733657de0f7f85dbf46c634dab4ff59
sha256: 812557c2aa0d39df9ba8e8c5f2ca460581fbe945925e41cc6eef541b60000da6
sha512: 98b8057068185e8b476d2589cc6e500f68b96ec139e7872431f92b7d3d85d76e6d44fed34428da7ff522b7bbd728d3d4521a780ef9d9b4ad4e164680b2c97b1e
ssdeep: 12288:3qgptCgj6RISXudHbOK93G9c6WXuVkkG62Pz3Q2DZyh+yAEb3JMWdFjxWc:3LCKsIyuFbQc6NkZcuZyhiWR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C15F1B6788295ACC50D4B35247755C0BAB72ACA3DE5CE0DB0DD430C5F2272BB352B6A
sha3_384: c20f46f095557c75d110da860a6be766b79e01c55a846277c1ad58058a34e091f853cd67cd763d2bf46562b84a0b7b30
ep_bytes: ff250020400000000000000000000000
timestamp: 2006-11-27 09:07:58

Version Info:

Translation: 0x0000 0x04b0
Comments: Random comments
CompanyName: Company name
FileDescription: IIS request monitor
FileVersion: 1.0.0.0
InternalName: 70014.exe
LegalCopyright: Copyright © 2008 - 2018. All rights reserved.
OriginalFilename: 70014.exe
ProductName: IIS request monitor
ProductVersion: 1.0.0.0
Assembly Version: 0.0.0.0

MSIL/Kryptik.QPE also known as:

LionicTrojan.Win32.Razy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Benin.3
FireEyeGeneric.mg.659cbcc428a122b4
McAfeePacked-FPW!659CBCC428A1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.MSIL.Agent.aeacv
K7AntiVirusTrojan ( 00545e451 )
AlibabaTrojan:MSIL/Kryptik.3168ee81
K7GWTrojan ( 00545e451 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/MSIL_Injector.QK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.QPE
APEXMalicious
KasperskyTrojan.MSIL.Agent.aeacv
BitDefenderGen:Heur.MSIL.Benin.3
NANO-AntivirusTrojan.Win32.Kryptik.fnyloy
AvastWin32:Trojan-gen
TencentMsil.Trojan.Agent.Wpaa
Ad-AwareGen:Heur.MSIL.Benin.3
SophosMal/Generic-S
ComodoMalware@#32pa5vpxf07hb
ZillyaTrojan.Kryptik.Win32.1599087
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Heur.MSIL.Benin.3 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.MSIL.Benin.3
AviraHEUR/AGEN.1101621
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.2A6A38A
ArcabitTrojan.MSIL.Benin.3
MicrosoftTrojan:Win32/Occamy.C
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4399008
BitDefenderThetaGen:NN.ZemsilF.34062.2m0@amnUbdo
YandexTrojan.Agent!tn6FNQvMoWY
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.QRG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.428a12
PandaTrj/GdSda.A

How to remove MSIL/Kryptik.QPE?

MSIL/Kryptik.QPE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment