Malware

MSIL/GenKryptik.EVNQ removal guide

Malware Removal

The MSIL/GenKryptik.EVNQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.EVNQ virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/GenKryptik.EVNQ?


File Info:

crc32: 914DFB8D
md5: da7635e6293c7f1afff0944b7e193043
name: upload_file
sha1: 199a772ac5d9ee21f056e7faf0a85b394cf5a159
sha256: 5a1dcba519c2976a2f610db7e6056f6fb42e56f0dd75224ad234c633ae192c33
sha512: cb1eb68b501484b252e537f69d869304884473001a5c160209825c74565b515f39e9e8b8efed75ba2e3b4f5cf11e4209f4396172fd15ea12ea387bc592425b08
ssdeep: 24576:xwvgA4WEEC5Ep24pgdioBDru8M0AbSEQqI5tumWRGaprirpSk:xwv9OBggdDQ85ApnrmWRGaprir
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016 - 2020
Assembly Version: 1.0.0.0
InternalName: Eglm.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Car Fixer
ProductVersion: 1.0.0.0
FileDescription: Car Fixer
OriginalFilename: Eglm.exe

MSIL/GenKryptik.EVNQ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.424
MicroWorld-eScanTrojan.GenericKD.35059119
FireEyeGeneric.mg.da7635e6293c7f1a
McAfeePWS-FCSU!DA7635E6293C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005722691 )
BitDefenderTrojan.GenericKD.35059119
K7GWTrojan ( 005722691 )
InvinceaMal/Generic-R + Troj/Kryptik-NC
BitDefenderThetaGen:NN.ZemsilCO.34590.3m0@a4qT4Jn
CyrenW32/MSIL_Kryptik.CBD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Agensla.7ebe7562
ViRobotTrojan.Win32.Z.Wacatac.916480.E
TencentMsil.Trojan-qqpass.Qqrob.Wstq
Ad-AwareTrojan.GenericKD.35059119
SophosTroj/Kryptik-NC
ComodoMalware@#1r7h6ownf6qhx
TrendMicroTrojanSpy.MSIL.AGENSLA.USMANK220
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftTrojan.GenericKD.35059119 (B)
IkarusTrojan.Inject
MicrosoftTrojanSpy:MSIL/Stelega.RIA!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D216F5AF
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.35059119
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Lokibot.R354623
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.PNG
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.EVNQ
TrendMicro-HouseCallTrojanSpy.MSIL.AGENSLA.USMANK220
SentinelOneDFI – Malicious PE
FortinetMalicious_Behavior.SB
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/Trojan.PSW.374

How to remove MSIL/GenKryptik.EVNQ?

MSIL/GenKryptik.EVNQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment