Malware

MSIL/GenKryptik.FZQG (file analysis)

Malware Removal

The MSIL/GenKryptik.FZQG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FZQG virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/GenKryptik.FZQG?


File Info:

name: B1841EFCBA198E805AF9.mlw
path: /opt/CAPEv2/storage/binaries/11a1458627eda1320ab9064d2df59e53cc3ca28086458ced1d3624cb5055738b
crc32: 610EB03B
md5: b1841efcba198e805af92d71584c5328
sha1: 34ddbee5ee8e1e60260668c0910237956a1be55b
sha256: 11a1458627eda1320ab9064d2df59e53cc3ca28086458ced1d3624cb5055738b
sha512: ca64b2c32f52d64e2be90e27e21a37d3819589647791823400422112b65701011e079e308bb025778ae3d480b11b462a9bb1cc5807db892f337bb0b4618a2a4d
ssdeep: 49152:bQzBRcZcPhwUKsynNd8flgf6Bag6OnOnNgZdn5le7Z72GvQfNfQRQytAYPi5TB:bQ1RciJwUKjNd6Q68g6ZnNgZFT072vKW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AD533EE13A528B1F3532DBC90ABAAAFD3BF9D53DD85B2991124602141F0BB1481C793
sha3_384: 8cf38fd8eafc280c43b9fdfcee15e64189f2420dc4b5a4090edb5cf62539c66754bede4d451364dc0d04ef072cc0e975
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-09-03 07:12:24

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0,0,0,0
InternalName: PDF Exploit.exe
LegalCopyright:
OriginalFilename: PDF Exploit.exe
ProductVersion: 0,0,0,0
Assembly Version: 0.0.0.0

MSIL/GenKryptik.FZQG also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.20338
FireEyeGeneric.mg.b1841efcba198e80
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/Azorult.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FZQG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderIL:Trojan.MSILZilla.20338
AvastWin32:CrypterX-gen [Trj]
Ad-AwareIL:Trojan.MSILZilla.20338
SophosGeneric ML PUA (PUA)
VIPREIL:Trojan.MSILZilla.20338
Trapminemalicious.high.ml.score
EmsisoftIL:Trojan.MSILZilla.20338 (B)
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILZilla.20338
AviraTR/Dropper.Gen
ArcabitIL:Trojan.MSILZilla.D4F72
MicrosoftTrojan:MSIL/RedLine.MC!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5194113
Acronissuspicious
ALYacIL:Trojan.MSILZilla.20338
MAXmalware (ai score=88)
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:tWFjQkhFA3f6oGdZIQM6sQ)
IkarusTrojan.MSIL.CoinMiner
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.FVDD!tr
BitDefenderThetaAI:Packer.F222395E1F
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.cba198

How to remove MSIL/GenKryptik.FZQG?

MSIL/GenKryptik.FZQG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment