Malware

Should I remove “MSIL/Kryptik.VMQ”?

Malware Removal

The MSIL/Kryptik.VMQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.VMQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Exhibits behavior characteristic of iSpy Keylogger
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

0.tcp.ngrok.io

How to determine MSIL/Kryptik.VMQ?


File Info:

crc32: 08FBDB9E
md5: 2c5b931410f5d83a3fbc3043db766a22
name: 2C5B931410F5D83A3FBC3043DB766A22.mlw
sha1: 62fa4b8690913bda526f8ec93622245a8d690e02
sha256: 2b188974c43a9df3814e2e2e1e6708daf86d6e131a2f98af9fe320d4a6abeda6
sha512: d1029aa888830fff9b82e1e74fda01909666e085fb56eaddd0cc8301a149d9bf2d9859fd88fa7bbf15c12769938e7a9dabdfff76575fa470057bb5c344769cf5
ssdeep: 1536:0YHYdLaOvdLG2uTneWW4aAr5ou68byL76:0FdLaP2upMAXxGL7
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: LQLock.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: LQLock.exe

MSIL/Kryptik.VMQ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader33.4312
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.618060
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.410f5d
CyrenW32/MSIL_Kryptik.CNZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.VMQ
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Ransomware.Encoder-9846353-0
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Razy.618060
MicroWorld-eScanGen:Variant.Razy.618060
Ad-AwareGen:Variant.Razy.618060
SophosML/PE-A
F-SecureTrojan.TR/Dropper.MSIL.Gen
BitDefenderThetaGen:NN.ZemsilF.34770.nm0@aut0NIp
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.2c5b931410f5d83a
EmsisoftGen:Variant.Razy.618060 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_96%
MicrosoftWorm:Win32/Ganelp
ArcabitTrojan.Razy.D96E4C
GDataGen:Variant.Razy.618060
AhnLab-V3Trojan/Win32.RL_Generic.C4012728
Acronissuspicious
McAfeeGenericRXKA-HQ!2C5B931410F5
MAXmalware (ai score=83)
MalwarebytesMachineLearning/Anomalous.97%
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.WFI!tr
AVGWin32:RATX-gen [Trj]
Qihoo-360HEUR/QVM03.0.4727.Malware.Gen

How to remove MSIL/Kryptik.VMQ?

MSIL/Kryptik.VMQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment