Malware

MSIL/Kryptik.ZGX removal

Malware Removal

The MSIL/Kryptik.ZGX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZGX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Unconventionial language used in binary resources: Polish
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
ureylarnalyoguentrad.online
nslandisteledthymber.online
rusixonhurgiletimeto.online

How to determine MSIL/Kryptik.ZGX?


File Info:

crc32: D07633B6
md5: f3cf8f0537c6ee14168733cf3cd82bb8
name: F3CF8F0537C6EE14168733CF3CD82BB8.mlw
sha1: 58a96b4d874e1d5ce03889ffe8ec1db4eee6dca8
sha256: a0959863dc0af86481f9f9c5322c348c2d71d157784db40aaa63b23ebed571df
sha512: 80dfdd23faba11abf0523779166714f915012068292a619d3eebfb52508a07c1acaf5e5db9218ffc41cf6e7452a0b8b5b19322968d534a96a1ae110890a05337
ssdeep: 12288:m1GXCyXakbQGzm9qTDF2xeshgH8uS73ntYaE+:Vm9qTDF2oshgS73Z
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

MSIL/Kryptik.ZGX also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36146132
CAT-QuickHealTrojan.Multi
McAfeeArtemis!F3CF8F0537C6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0057644c1 )
BitDefenderTrojan.GenericKD.36146132
K7GWTrojan ( 0057644c1 )
Cybereasonmalicious.d874e1
ArcabitTrojan.Generic.D2278BD4
CyrenW32/Trojan.VAVF-2184
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.blft
AlibabaTrojanSpy:Win32/SpyEyes.7a42a218
RisingBackdoor.Remcos!8.B89E (TFE:1:KwFKbqSl0IK)
Ad-AwareTrojan.GenericKD.36146132
SophosMal/Generic-R + Mal/EncPk-APW
ComodoTrojWare.Win32.Genome.oyqoi@0
F-SecureTrojan.TR/AD.TriumphLoader.W
ZillyaTrojan.SpyEyes.Win32.15181
TrendMicroTROJ_GEN.R002C0RAK21
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.f3cf8f0537c6ee14
EmsisoftTrojan.GenericKD.36146132 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.SpyEyes.pkq
WebrootW32.Trojan.Gen
AviraTR/AD.TriumphLoader.W
MAXmalware (ai score=82)
GridinsoftTrojan.Win32.Kryptik.vb
MicrosoftTrojan:Win32/Ymacco.AAA0
ZoneAlarmTrojan-Spy.Win32.SpyEyes.blft
GDataTrojan.GenericKD.36146132
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R363579
VBA32TrojanSpy.SpyEyes
ALYacTrojan.GenericKD.36146132
MalwarebytesMalware.Heuristic.1003
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.ZGX
TrendMicro-HouseCallTROJ_GEN.R002C0RAK21
TencentWin32.Trojan-spy.Spyeyes.Edxn
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.ZGX!tr
BitDefenderThetaGen:NN.ZexaF.34780.1mW@aq09u!hG
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM19.1.ACA7.Malware.Gen

How to remove MSIL/Kryptik.ZGX?

MSIL/Kryptik.ZGX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment