Categories: Malware

MSIL/Kryptik.WQX information

The MSIL/Kryptik.WQX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.WQX virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
GRuWmqSjGY.GRuWmqSjGY
www.bing.com
iplogger.org
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine MSIL/Kryptik.WQX?


File Info:

crc32: E95B4811md5: 42a5d1549c67b9ac52d5906b5e03bc53name: upload_filesha1: da0b41800eab70cdcc8d6703343b0412de364c52sha256: 0c805f663b13aa8b836228e8bfb82484df7068f8a6b81abac49ced8ce37f0e53sha512: e547e13569d15033677bb46eaa031845bb6e79722b0dc5f022fbafaef50cb3902e6c48c7213800ce849f384417885bc56c89e97d07f84a11d66f7549321b41c0ssdeep: 49152:Ey6mwoOla4A9fmmcGLxjImg4hDG5AAdUMwCI:F6mwJ8RmmcwjIuQ+qfetype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: FileVersion: CompanyName: Speedup inc Comments: This installation was built with Inno Setup.ProductName: Speedup ProductVersion: 4.8 FileDescription: Speedup Setup Translation: 0x0000 0x04b0

MSIL/Kryptik.WQX also known as:

MicroWorld-eScan Trojan.GenericKD.43430568
FireEye Trojan.GenericKD.43430568
McAfee Artemis!42A5D1549C67
BitDefender Trojan.GenericKD.43430568
BitDefenderTheta Gen:NN.ZemsilF.34130.ar1@a019DLb
ESET-NOD32 a variant of MSIL/Kryptik.WQX
GData Trojan.GenericKD.43430568
Kaspersky HEUR:Trojan.MSIL.Chapak.gen
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.VidarStealer.fjimu
Emsisoft Trojan.GenericKD.43430568 (B)
Jiangmin Backdoor.ZAccess.lj
Avira appv.exe
Microsoft Trojan:MSIL/TeslaCrypt.VN!MTB
AhnLab-V3 Trojan/Win32.Agent.C4014674
ZoneAlarm HEUR:Trojan.MSIL.Chapak.gen
MAX malware (ai score=87)
Malwarebytes Trojan.Dropper
Ikarus Trojan.MSIL.Agent
Webroot W32.Adware.Gen
Qihoo-360 HEUR/QVM06.1.5304.Malware.Gen

How to remove MSIL/Kryptik.WQX?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan.Win32.Agent.xbnasm removal guide

The Trojan.Win32.Agent.xbnasm is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

Zusy.541701 malicious file

The Zusy.541701 is considered dangerous by lots of security experts. When this infection is active,…

19 mins ago

Worm.Win32.Vobfus.dglv removal instruction

The Worm.Win32.Vobfus.dglv is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Trojan.Win32.Agent.xblgia removal instruction

The Trojan.Win32.Agent.xblgia is considered dangerous by lots of security experts. When this infection is active,…

25 mins ago

Tedy.463818 removal

The Tedy.463818 is considered dangerous by lots of security experts. When this infection is active,…

30 mins ago

Malware.AI.4231027217 removal tips

The Malware.AI.4231027217 is considered dangerous by lots of security experts. When this infection is active,…

30 mins ago