Malware

Should I remove “MSIL/Kryptik.ZEW”?

Malware Removal

The MSIL/Kryptik.ZEW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZEW virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ZEW?


File Info:

crc32: D899CB16
md5: 2e33c8107d609a10b663938265100b06
name: 2E33C8107D609A10B663938265100B06.mlw
sha1: 14352082be2c9bc41159032c01167093fa69a192
sha256: db4c881143fdac0f6a8cd52e07c4093fdf0a4b6887091dcacc69cd1de9f6307f
sha512: 51ad3b4026eaa5d9690003922d7ced7c3a17654be348d5543582cb6f001327e11cd83ba22736f546192d59cfd61491ea909b7266576d5cf2b13e9ad7ddedc191
ssdeep: 12288:a1dVVyBfUDiA4Mdz+6YTlvMd5Qa//1lSJFVxAUQyG:cVVy1UDMMdy6YCvPHzUFVx/QH
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017-2021 Sobhan Darou
Assembly Version: 23.8.0.0
InternalName: x641P.exe
FileVersion: 29.0.0.0
CompanyName: Sobhan Darou
LegalTrademarks:
Comments: Exir Pharma
ProductName: Exir Pharma
ProductVersion: 29.0.0.0
FileDescription: Exir Pharma
OriginalFilename: x641P.exe

MSIL/Kryptik.ZEW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45370155
FireEyeTrojan.GenericKD.45370155
CAT-QuickHealTrojan.Zew
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPREWin32.Malware!Drop
AegisLabTrojan.MSIL.Androm.m!c
SangforMalware
K7AntiVirusTrojan ( 00575c451 )
BitDefenderTrojan.GenericKD.45370155
K7GWTrojan ( 00575c451 )
CyrenW32/MSIL_Kryptik.CPA.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaTrojan:Win32/csharp.ali2000008
ViRobotTrojan.Win32.Z.Kryptik.678400.V
TencentMsil.Backdoor.Androm.Hsit
Ad-AwareTrojan.GenericKD.45370155
EmsisoftTrojan.GenericKD.45370155 (B)
ComodoMalware@#37svvkjivxgqg
F-SecureTrojan.TR/AD.LokiBot.javmm
DrWebTrojan.PWS.Stealer.23680
ZillyaTrojan.Kryptik.Win32.2812413
TrendMicroTrojanSpy.MSIL.LOKI.CLPB
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S + Troj/Steal-AZE
IkarusTrojan.MSIL.Inject
JiangminBackdoor.MSIL.edjk
AviraTR/AD.LokiBot.javmm
Antiy-AVLTrojan/MSIL.Kryptik
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.AM!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B44B2B
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.GenericKD.45370155
CynetMalicious (score: 90)
AhnLab-V3Malware/Win32.RL_Generic.C4292494
VBA32TScope.Trojan.MSIL
ALYacSpyware.LokiBot
MAXmalware (ai score=95)
MalwarebytesSpyware.TelegramBot
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.ZEW
TrendMicro-HouseCallTrojanSpy.MSIL.LOKI.CLPB
YandexTrojan.Kryptik!Hh5cQsKP/7c
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.ZEW!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Backdoor.9cf

How to remove MSIL/Kryptik.ZEW?

MSIL/Kryptik.ZEW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment