Malware

MSIL/GenKryptik.FORC removal

Malware Removal

The MSIL/GenKryptik.FORC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FORC virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine MSIL/GenKryptik.FORC?


File Info:

name: A15419DF02FFAE775B62.mlw
path: /opt/CAPEv2/storage/binaries/511d45db9f19d470d7c4af3afef0c99e66e4fbae53128f9bc12481477751438b
crc32: EA57367D
md5: a15419df02ffae775b6231dd77fd9c6f
sha1: f3c27642060afb3d062ad82e11986153781809b6
sha256: 511d45db9f19d470d7c4af3afef0c99e66e4fbae53128f9bc12481477751438b
sha512: 552640f4f735ad040697cd4a6786e20fae7f122b921c539ff65be9b5a4a6261e67dcbf50b29ffffa80e9d27f7816a74e759c1db1a3107ec58a55552b4ddeb415
ssdeep: 6144:MkZOQVFAJnj/Shond2MDuzwAeZgmsMOGZ/+6THtQM/+3:BUQVF4nj/godHDuMPsMOGV+6TN5C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC74CE5003E40B8AF1F22FB56DF105015F31B692AD32EB4D0EC4A5E948B9B958F79B1B
sha3_384: 6116dea86b0e4120cf13b821e0a7700d95aa243d802e4b21b54e002f2a0b72e63d4e14860f1db0f604c855e338f55e7a
ep_bytes: ff250020400000000000000000000000
timestamp: 2092-10-21 05:56:18

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft Corporation
FileDescription: Microsoft.VisualStudio.Web.BrowserLink.12.0
FileVersion: 16.6.936.3669
InternalName: Microsoft.VisualStudio.Web.BrowserLink.12.0.dll
LegalCopyright: ? Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: Microsoft.VisualStudio.Web.BrowserLink.12.0.dll
ProductName: Microsoft.VisualStudio.Web.BrowserLink.12.0
ProductVersion: 16.6.936-preview3+550e59c1ad
Assembly Version: 16.0.0.0

MSIL/GenKryptik.FORC also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.34720
MicroWorld-eScanTrojan.GenericKD.38251804
FireEyeGeneric.mg.a15419df02ffae77
ALYacTrojan.GenericKD.38251804
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058bb721 )
AlibabaTrojan:MSIL/GenKryptik.c7f5054e
K7GWTrojan ( 0058bb721 )
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderThetaGen:NN.ZemsilF.34084.wm0@a423soe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FORC
TrendMicro-HouseCallTROJ_FRS.0NA103LD21
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderTrojan.GenericKD.38251804
Ad-AwareTrojan.GenericKD.38251804
EmsisoftTrojan.GenericKD.38251804 (B)
Comodo.UnclassifiedMalware@0
TrendMicroTROJ_FRS.0NA103LD21
McAfee-GW-EditionRDN/Wacapew
SophosGeneric PUA PD (PUA)
Paloaltogeneric.ml
AviraTR/AD.Inject.jktuk
KingsoftWin32.Troj.Generic_a.a.(kcloud)
GridinsoftTrojan.Win32.Downloader.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataTrojan.GenericKD.38251804
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Wacapew.C4844002
McAfeeRDN/Wacapew
MAXmalware (ai score=85)
CylanceUnsafe
APEXMalicious
YandexTrojan.Crypt!kYqSJIxd1ik
SentinelOneStatic AI – Malicious PE
FortinetMalicious_Behavior.SB
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.2060af
PandaTrj/GdSda.A

How to remove MSIL/GenKryptik.FORC?

MSIL/GenKryptik.FORC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment