Malware

MSIL/Kryptik.ZQA removal

Malware Removal

The MSIL/Kryptik.ZQA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZQA virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ZQA?


File Info:

crc32: B3B2ED9A
md5: e7e3d5a50a34d4b1c5ba9be05e810624
name: E7E3D5A50A34D4B1C5BA9BE05E810624.mlw
sha1: ae68ae3445dff4fd7e1ee380819551a52fff0b77
sha256: 222165dd7723dadb40fa68e27857cfe28d44c75eb1eb14dd13ea2861d900c473
sha512: 42631bbce81330a8e0e0d915903cea7feff00625e7d61ffa6a2b98aced49fb9197366b9e34462b16aa8a27e8f559c7c3a362abc082b79903602228ca0a906409
ssdeep: 12288:YSd5NVdXaJLyQ11CYBhQV3SJ6fNxfmSmyyztGb2oZCbH:/VdXa1gY88WTfmyyEbAb
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2019
Assembly Version: 1.1.0.0
InternalName: CallingConvention.exe
FileVersion: 1.1.0.0
CompanyName: Budapest Luxury
LegalTrademarks:
Comments:
ProductName: BAP PROJECT
ProductVersion: 1.1.0.0
FileDescription: BAP PROJECT
OriginalFilename: CallingConvention.exe

MSIL/Kryptik.ZQA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36326962
FireEyeTrojan.GenericKD.36326962
ALYacTrojan.GenericKD.36326962
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00577a421 )
BitDefenderTrojan.GenericKD.36326962
K7GWTrojan ( 00577a421 )
CyrenW32/MSIL_Kryptik.DBQ.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Tnega.880e2e6d
ViRobotTrojan.Win32.Z.Kryptik.648192.Z
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-qqpass.Qqrob.Anfn
Ad-AwareTrojan.GenericKD.36326962
EmsisoftTrojan.GenericKD.36326962 (B)
ComodoMalware@#2xx4u884bsdyi
F-SecureTrojan.TR/AD.XetimaLogger.vauvu
DrWebTrojan.PackedNET.540
TrendMicroTROJ_FRS.0NA103BC21
McAfee-GW-EditionRDN/Generic.grp
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
JiangminTrojan.PSW.MSIL.bgje
WebrootW32.Trojan.Gen
AviraTR/AD.XetimaLogger.vauvu
Antiy-AVLTrojan/Win32.Generic
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Tnega.VA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D22A4E32
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.36326962
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R366269
McAfeeRDN/Generic.grp
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.PNG.Generic
ESET-NOD32a variant of MSIL/Kryptik.ZQA
TrendMicro-HouseCallTROJ_FRS.0NA103BC21
SentinelOneStatic AI – Malicious PE
FortinetW32/Agensla.ZQA!tr.pws
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
Qihoo-360Win32/TrojanSpy.AgentTesla.HgIASOwA

How to remove MSIL/Kryptik.ZQA?

MSIL/Kryptik.ZQA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment