Malware

MSIL/GenKryptik.EDSE (file analysis)

Malware Removal

The MSIL/GenKryptik.EDSE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.EDSE virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSIL/GenKryptik.EDSE?


File Info:

name: 85C0D6E0510033654581.mlw
path: /opt/CAPEv2/storage/binaries/7386d25f7577a3fec96b10be0adcd60b14e2de8ad6be2a4ef24ad1950fbff751
crc32: 8AC0783C
md5: 85c0d6e0510033654581d9b4eb419e31
sha1: 20f3ab6e77f4fc8fb639b9f90982a53405c19c3d
sha256: 7386d25f7577a3fec96b10be0adcd60b14e2de8ad6be2a4ef24ad1950fbff751
sha512: 1c68f17a06d4721f76c62f775258470822f58711b7f94e4b385680026ab8b2d883bf11720deab26feb6e5e9dc2d8674556a0f42f891a1c7b3d9feb9da90d14e1
ssdeep: 6144:Y3xa2aCv2GhNhnbmRciG/moNITeAkDYpnCjSSS8OntkE+i0cYLa8cK9kmwh/rXpP:0xa2aCv2iN6ciasTetY0hShntwi3H4wx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F746CD32B290A0CC8B8E8B4444FE11424D5B79D99239C1D09EF74BB644BAD73BA5C7E
sha3_384: b9a16b303fdff9fa6e0f1e11d0185e1dca7b2c8f7caef7ed98e436dc40a3142563309f5c2a19d4d8ddf8d6148a34c40c
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-01-21 14:20:06

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WindowsFormsApplication1
FileVersion: 1.0.0.0
InternalName: Stub.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: Stub.exe
ProductName: WindowsFormsApplication1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/GenKryptik.EDSE also known as:

BkavW32.Common.24E3AEF7
LionicTrojan.Win32.Noon.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68779089
Cylanceunsafe
SangforSuspicious.Win32.Save.a
AlibabaTrojanSpy:MSIL/GenKryptik.9feeac6d
Cybereasonmalicious.e77f4f
CyrenW32/ABRisk.BAQI-0060
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.EDSE
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.68779089
AvastWin32:RATX-gen [Trj]
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.AgentTesla.fc
FireEyeGeneric.mg.85c0d6e051003365
EmsisoftTrojan.GenericKD.68779089 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.68779089
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/MSIL.GenKryptik
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0CHH23
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:rp0wG8whOJ7bg4WCivmfEQ)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.EDSE!tr
BitDefenderThetaGen:NN.ZemsilF.36350.wm0@aWLFIle
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/GenKryptik.EDSE?

MSIL/GenKryptik.EDSE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment