Malware

About “MSIL/Kryptik.WGM” infection

Malware Removal

The MSIL/Kryptik.WGM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.WGM virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine MSIL/Kryptik.WGM?


File Info:

crc32: D9DC240B
md5: bb3525d5e025125426420f276a81e365
name: buazo.exe
sha1: 1cb5127c89db4afc68316246be6845517446befa
sha256: 1bf83b4a93bb142987bdecf264dd3fed87ddc449a26fdb5b6e4d731a5fb7d211
sha512: adb138ed265bdaa7a0c016f02a704de4f675332fcc9ec9c1dc652912077aabaf9df4c0ee29a27c6527b552415e3cef98a0b5cb729b4866dba1b040d271c8a126
ssdeep: 6144:6sgJRo7aH8t+Eg38+B8qshFokWRFL7wbh5Mp1Ey9nd9CCylJWnKskHot54rTJfF:QRAdv68+6qshFo13L7wbnMjFdErlJWn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: IntensifyCore
Assembly Version: 1.0.0.0
InternalName: TdsmqLeCt.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: IntensifyCore.Properties
ProductVersion: 1.0.0.0
FileDescription: IntensifyCore
OriginalFilename: TdsmqLeCt.exe

MSIL/Kryptik.WGM also known as:

FireEyeGeneric.mg.bb3525d5e0251254
SangforMalware
Cybereasonmalicious.c89db4
BitDefenderThetaGen:NN.ZemsilF.34128.tm0@aqO5Jwe
AvastWin32:PWSX-gen [Trj]
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
APEXMalicious
WebrootW32.Trojan.Gen
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Wacatac.D!ml
ESET-NOD32a variant of MSIL/Kryptik.WGM
SentinelOneDFI – Malicious PE
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360HEUR/QVM03.0.CF43.Malware.Gen

How to remove MSIL/Kryptik.WGM?

MSIL/Kryptik.WGM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment