Malware

Should I remove “MSIL:Crypt-SG [Trj]”?

Malware Removal

The MSIL:Crypt-SG [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL:Crypt-SG [Trj] virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL:Crypt-SG [Trj]?


File Info:

crc32: 19BBF8C4
md5: 950595d5acae4fa6267834ced85cc2f7
name: 950595D5ACAE4FA6267834CED85CC2F7.mlw
sha1: a60d1790dce82004c6e797655a68b55f6bf8d56a
sha256: 1db8485ba09a0c112fbc79b6493d41a5e079c8ae5f5d3c904e03ed4f95759c38
sha512: 40741173c7f7a3bc1900ca7fbb77a3b7c7fd67d40309a155bb2c297e9b3b17fa083a3c63c214a0b4cce563b7918dcd749486a1d05384b0ca8503f648c13d199d
ssdeep: 3072:d1ioDvolI21OIiO4zOghqTpqceEamTi8LlwBm:d1iWvolVclOeptEzZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL:Crypt-SG [Trj] also known as:

K7AntiVirusTrojan ( 004be4791 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.25074
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004be4791 )
Cybereasonmalicious.5acae4
CyrenW32/Ransom.AY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.BYG
APEXMalicious
AvastMSIL:Crypt-SG [Trj]
KasperskyHEUR:Trojan.MSIL.DOTHETUK.gen
NANO-AntivirusTrojan.Win32.Zapchast.ctqirs
TencentWin32.Trojan.Generic.Hqkz
SophosMal/Generic-S
ComodoMalware@#1lbflspg9uhut
BitDefenderThetaGen:NN.ZemsilF.34266.nmW@ayVz8Bo
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.950595d5acae4fa6
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.7007AC
KingsoftWin32.Troj.Zapchast.bn.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.AA
AhnLab-V3Trojan/Win32.Inject.C216362
Acronissuspicious
McAfeeArtemis!950595D5ACAE
VBA32Trojan.MSIL.Zapchast
MalwarebytesBackdoor.Bladabindi.MSIL
PandaGeneric Malware
YandexTrojan.Zapchast!7QBSA6TjJCw
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.BYG!tr
AVGMSIL:Crypt-SG [Trj]
Paloaltogeneric.ml

How to remove MSIL:Crypt-SG [Trj]?

MSIL:Crypt-SG [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment