Malware

MSIL/Kryptik.JTQ.Gen removal tips

Malware Removal

The MSIL/Kryptik.JTQ.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.JTQ.Gen virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.JTQ.Gen?


File Info:

name: 4AFA0DBB1223F71C7306.mlw
path: /opt/CAPEv2/storage/binaries/b239fd1fcb8584904df2bd769c8546c398fb659a70fb14b1e42d3d3bec2971e4
crc32: CDD2CA9C
md5: 4afa0dbb1223f71c7306d9d25a271cd1
sha1: 9460d9876e15af6f0286c958459747033c773e16
sha256: b239fd1fcb8584904df2bd769c8546c398fb659a70fb14b1e42d3d3bec2971e4
sha512: 73fdd09155439c0f02ebffb0cf8042b9dd588e374194e8b5efee39a61921c6b4f60c9b10bfe3a5c3988f72dd600cf10b1dd78fb8ec688c75887362ca293a3e0b
ssdeep: 49152:u78LjPHlN3ENm6IZxqsSEImrt1FpFeLICvjUUpyRt+WjU+1wANtgxB:u78lpDZ9ImrBrk1gU2t+3f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121E5E1613941CD13E1ED53FAC9DB904483B86C026A6ACF5ABE9B73ED11017A75C0E9CB
sha3_384: 0dad8a13df0c1f61faab6766802b485daffba5c9d50df3e7401e2d398a0c6ee29e4e1fe211a37725ea85557e21875c28
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-06-26 13:48:06

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Cindy Restaurant
FileVersion: 1.0.0.0
InternalName: Cindy Restaurant.exe
LegalCopyright: Copyright © 2017
OriginalFilename: Cindy Restaurant.exe
ProductName: Cindy Restaurant
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.JTQ.Gen also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILPerseus.114257
FireEyeGeneric.mg.4afa0dbb1223f71c
ALYacGen:Variant.MSILPerseus.114257
CylanceUnsafe
SangforBackdoor.MSIL.Generic.ky
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:MSIL/Kryptik.5ad7bece
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.b1223f
VirITTrojan.Win32.Dnldr22.RHD
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Kryptik.JTQ.Gen
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Backdoor.MSIL.Generic
BitDefenderGen:Variant.MSILPerseus.114257
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10bae113
Ad-AwareGen:Variant.MSILPerseus.114257
SophosMal/Generic-S
DrWebTrojan.DownLoader22.11677
TrendMicroTROJ_GEN.R002C0PB822
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
EmsisoftGen:Variant.MSILPerseus.114257 (B)
GDataMSIL.Backdoor.Quasar.XT4TGC
AviraHEUR/AGEN.1203202
Antiy-AVLTrojan/Generic.ASMalwS.20F56AC
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win32.Krypt.R210423
McAfeeTrojan-FPLA!4AFA0DBB1223
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.BetaBot
TrendMicro-HouseCallTROJ_GEN.R002C0PB822
YandexTrojan.DownLoader!aG9+JR23/cg
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.ZHE!tr
BitDefenderThetaGen:NN.ZemsilF.34212.!s3@aSIMBCl
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove MSIL/Kryptik.JTQ.Gen?

MSIL/Kryptik.JTQ.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment