Malware

Should I remove “MSIL/Kryptik.MGQ”?

Malware Removal

The MSIL/Kryptik.MGQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.MGQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.MGQ?


File Info:

crc32: 55AE2E4D
md5: 2608f00ad19f9d4de84a141bc3809d4a
name: 2608F00AD19F9D4DE84A141BC3809D4A.mlw
sha1: d447b36d37036c06b45ec09e17be778e08666d53
sha256: 03bf8e748f8f673576a9739641ba933dbcd57e40f99ae8e76455e8910807e3e0
sha512: edbbbc943414f9fa8aaa18d7a0cb70d60b78ac6ada313efeaf204945eb2d62935f7310f281940d6240b372277109375917ac73e7cd697c45c61e295590d6aedf
ssdeep: 12288:h23JXNycPf2rihL0Mm2QxIqSZi8YwtiOzbIkTeX:hdqkfSs8Y3tkTi
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: spoolsv.exe
FileVersion: 10.0.17134.1 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.17134.1
FileDescription: Spooler SubSystem App
OriginalFilename: spoolsv.exe
Translation: 0x0409 0x04b0

MSIL/Kryptik.MGQ also known as:

K7AntiVirusTrojan ( 00524a431 )
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.13678
CynetMalicious (score: 99)
ALYacGen:Heur.MSIL.Krypt.!cdmip!.2
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Kryptik.941f74ff
K7GWTrojan ( 00524a431 )
Cybereasonmalicious.ad19f9
ESET-NOD32a variant of MSIL/Kryptik.MGQ
APEXMalicious
ClamAVWin.Packed.njRAT-9799369-1
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Heur.MSIL.Krypt.!cdmip!.2
NANO-AntivirusTrojan.Win32.Bladabindi.fdygqw
MicroWorld-eScanGen:Heur.MSIL.Krypt.!cdmip!.2
TencentMsil.Trojan.Generic.Hoeq
Ad-AwareGen:Heur.MSIL.Krypt.!cdmip!.2
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34236.Nm0@aKqyN8fi
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.2608f00ad19f9d4d
EmsisoftGen:Heur.MSIL.Krypt.!cdmip!.2 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1119530
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2697607
GDataGen:Heur.MSIL.Krypt.!cdmip!.2
AhnLab-V3Trojan/Win32.MSILKrypt.C2560262
MAXmalware (ai score=99)
PandaTrj/GdSda.A
YandexTrojan.Agent!rwXqPvKuhIw
IkarusTrojan.MSIL.Injector
FortinetMSIL/Kryptik.GVM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove MSIL/Kryptik.MGQ?

MSIL/Kryptik.MGQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment