Malware

MSIL/Kryptik.ZUQ removal

Malware Removal

The MSIL/Kryptik.ZUQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ZUQ virus can do?

  • The binary likely contains encrypted or compressed data.

How to determine MSIL/Kryptik.ZUQ?


File Info:

crc32: 987CE5D4
md5: 1198c4b14b5ee8eab8412310498ef31b
name: 1198C4B14B5EE8EAB8412310498EF31B.mlw
sha1: f08c2ff75da2c4a123896d5384c071d2710a23f4
sha256: 3c261a74e4a4d9bc516198b946d0a5907c0b1d71a3af960db45f8bfa700e3203
sha512: 7ced723ea430633ca13d4d64846d715578bc5f30dcdb413309023620e204a5c9713e8c1de383ca366b015ce521ee0b3b482e529f917899698d73a1d36217694e
ssdeep: 24576:/7OzkOwUmV35QWxMSG8gw9UKSmdAapqmmdKmjxk:uCfxG/wSKhAapq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.8
InternalName: Empty.exe
FileVersion: 1.0.0.8
CompanyName:
LegalTrademarks:
Comments: Placement System
ProductName: Placement System
ProductVersion: 1.0.0.8
FileDescription: Placement System
OriginalFilename: Empty.exe

MSIL/Kryptik.ZUQ also known as:

K7AntiVirusTrojan ( 0057883d1 )
Elasticmalicious (high confidence)
DrWebBackDoor.SpyBotNET.25
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Multi
ALYacTrojan.GenericKD.45806300
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/Kryptik.bf45566a
K7GWTrojan ( 0057883d1 )
Cybereasonmalicious.14b5ee
CyrenW32/MSIL_Kryptik.CYQ.gen!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.ZUQ
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.45806300
NANO-AntivirusTrojan.Win32.Agensla.inmeuu
MicroWorld-eScanTrojan.GenericKD.45806300
TencentMsil.Trojan-qqpass.Qqrob.Dwtk
Ad-AwareTrojan.GenericKD.45806300
SophosMal/Generic-S
F-SecureTrojan.TR/Redcap.dfbpp
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTrojanSpy.Win32.SUSPECTCRC.USMANBS21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeTrojan.GenericKD.45806300
EmsisoftTrojan.GenericKD.45806300 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Redcap.dfbpp
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan[PSW]/MSIL.Agensla
MicrosoftTrojan:MSIL/Kryptik.VC!MTB
ArcabitTrojan.Generic.D2BAF2DC
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKD.45806300
AhnLab-V3Malware/Gen.RL_Reputation.C4351793
McAfeeGenericRXNT-WE!1198C4B14B5E
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.SUSPECTCRC.USMANBS21
RisingMalware.Undefined!8.C (CLOUD)
IkarusTrojan.Inject
FortinetMalicious_Behavior.SB
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.AgentTesla.HgIASP4A

How to remove MSIL/Kryptik.ZUQ?

MSIL/Kryptik.ZUQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment