Malware

MSIL/Kryptik.ZQG information

Malware Removal

The MSIL/Kryptik.ZQG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZQG virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ZQG?


File Info:

crc32: 04481EF4
md5: 26ed749390d4a00fff4181a61c306198
name: 26ED749390D4A00FFF4181A61C306198.mlw
sha1: 84e762f9d06f95260ed399bb0442e02b98102ff5
sha256: caee9387d7ef6216014c68f4acb557c2eaee0b6e9dd79141288eb1d9d06bf30c
sha512: 6ab29388801f5c9a3c7d4292d6b3cdfffa7b02d5eec524e33859e2b5caedcbd47016b463a00300379b7d41ac1db48d961f772ce0f2c5d783a0d338e9a32d65b5
ssdeep: 12288:AZVdXBqcl6d+vYf08dJOcruwLaS8iwRnGv3U0kxChx45:AZVdXAcIdoYf08dTr/98zQkxChx45
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Zoom Video Communications, Inc. All rights reserved.
InternalName: Zoom Meetings Installer
FileVersion: 5,4,0,0
CompanyName: Zoom Video Communications, Inc.
LegalTrademarks: Zoom Meetings Installer
Comments: Zoom Meetings Installer
ProductName: Zoom Meetings Installer
ProductVersion: 5,4,0,0
FileDescription: Zoom Meetings Installer
OriginalFilename: Zoom Meetings Installer
Translation: 0x0409 0x04e4

MSIL/Kryptik.ZQG also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.540
MicroWorld-eScanTrojan.GenericKD.45714348
FireEyeGeneric.mg.26ed749390d4a00f
McAfeePWS-FCUF!26ED749390D4
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00577b1f1 )
BitDefenderTrojan.GenericKD.45714348
K7GWTrojan ( 00577b1f1 )
Cybereasonmalicious.9d06f9
BitDefenderThetaGen:NN.ZemsilF.34574.an0@aqBexdcO
CyrenW32/MSIL_Kryptik.CPN.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
RisingSpyware.Stealer!8.3090 (CLOUD)
Ad-AwareTrojan.GenericKD.45714348
EmsisoftTrojan.Crypt (A)
ComodoMalware@#346y7zbjba2fn
F-SecureTrojan.TR/AD.RedLineSteal.jzvgf
TrendMicroTrojan.MSIL.MALREP.THBAEBA
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
AviraTR/AD.RedLineSteal.jzvgf
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanSpy:MSIL/Stelega.VA!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D2B98BAC
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
GDataMSIL.Malware.Injector.KVYTW0
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.C4332605
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.45714348
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.ZQG
TrendMicro-HouseCallTrojan.MSIL.MALREP.THBAEBA
TencentMsil.Trojan-spy.Stealer.Htmr
YandexTrojan.Kryptik!loZCLjlaS18
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73709669.susgen
FortinetMSIL/Kryptik.ZPV!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/TrojanSpy.Generic.HgIASO4A

How to remove MSIL/Kryptik.ZQG?

MSIL/Kryptik.ZQG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment