Malware

MSIL/Kryptik.XEI (file analysis)

Malware Removal

The MSIL/Kryptik.XEI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.XEI virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.XEI?


File Info:

crc32: DA52CE31
md5: a51b0e45f72d4a6249912da6538c6e2c
name: PO 300720-FMB.scr
sha1: c72bdfdbef4a47f1028d405a3a40513a257e3092
sha256: a1e30a2a09896194a7b457401dd3a9b405b53aeea17a21ca6b99b2e8da5e2876
sha512: 4b365b0e1cd0adbbc0c5a2ac0069c8576b4286e019f659f4a85530bd149b3b2fab0f955d753ad978c5223c56f76a996abcde78db60f6eb1c2e097fad1266095c
ssdeep: 12288:rLzzBCjL5HfjNB6QwfDx2v1okpTftbA/Lqv2jf1Li8figQI2cThd:rLpyp36QCx2vHtKjRD1fQI2cThd
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Massapequa Public School District 2012 - 2020
Assembly Version: 1.0.0.0
InternalName: SYEHnkyXES.exe
FileVersion: 1.0.0.0
CompanyName: Massapequa Public School District
LegalTrademarks:
Comments:
ProductName: Tetris
ProductVersion: 1.0.0.0
FileDescription: Tetris
OriginalFilename: SYEHnkyXES.exe

MSIL/Kryptik.XEI also known as:

MicroWorld-eScanTrojan.GenericKD.43568343
FireEyeGeneric.mg.a51b0e45f72d4a62
McAfeeRDN/Generic BackDoor
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056761d1 )
BitDefenderTrojan.GenericKD.43568343
K7GWTrojan ( 0056761d1 )
Cybereasonmalicious.bef4a4
TrendMicroTROJ_GEN.R03BC0DH120
F-ProtW32/MSIL_Kryptik.BGJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.43568343
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
AlibabaTrojan:Win32/starter.ali1000139
AegisLabTrojan.MSIL.NanoBot.m!c
Ad-AwareTrojan.GenericKD.43568343
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.MSIL.gytum
Invinceaheuristic
EmsisoftTrojan.GenericKD.43568343 (B)
IkarusTrojan.MSIL.Inject
CyrenW32/MSIL_Kryptik.BGJ.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Dropper.MSIL.gytum
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D298CCD7
ZoneAlarmHEUR:Backdoor.MSIL.NanoBot.gen
MicrosoftTrojan:MSIL/TeslaCrypt.A!MTB
BitDefenderThetaGen:NN.ZemsilF.34144.Nm0@a4cZn1j
ALYacTrojan.GenericKD.43568343
MAXmalware (ai score=87)
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of MSIL/Kryptik.XEI
TrendMicro-HouseCallTROJ_GEN.R03BC0DH120
RisingBackdoor.NanoBot!8.28C (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Backdoor.BO.5c9

How to remove MSIL/Kryptik.XEI?

MSIL/Kryptik.XEI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment