Malware

MSIL/GenKryptik.ELMN (file analysis)

Malware Removal

The MSIL/GenKryptik.ELMN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.ELMN virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/GenKryptik.ELMN?


File Info:

crc32: 1EB3129E
md5: 55acde4bde2328acaa98686353a4d45c
name: citrix.exe
sha1: 59e45bf83c77389618ac17f3d6be31fea583eb2f
sha256: 1e9a9c7ed29859e1f5c10fcb87f61717c3ccc5d798f6e400d5a60d5398279e65
sha512: 1abee94baa7df82ce7f929fba766ecab1b5f2a406f9441b32db9304961c3c2800db2975d004eea56734683ceef3defb07fd678009acecc5da046fbaa4c2d67fc
ssdeep: 3072:M7KEM0dTjM54VizjfM/AnGBLnVMx4VZpn+uirFeRXqiRmBcj2hl9qs0zy4jH:M7i025swr9n2LnVMOPjiCqNhTh05
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: XzMQdlW
Assembly Version: 1.0.0.0
InternalName: XzMQdlW.exe
FileVersion: 1.0.0.0
LegalTrademarks: hAIehAp
Comments: hAIehAp
ProductName: XzMQdlW
ProductVersion: 1.0.0.0
FileDescription: hAIehAp
OriginalFilename: XzMQdlW.exe

MSIL/GenKryptik.ELMN also known as:

MicroWorld-eScanTrojan.GenericKD.43251965
CAT-QuickHealTrojan.MSIL
ALYacTrojan.GenericKD.43251965
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.ClipBanker.7!c
SangforMalware
K7AntiVirusTrojan ( 00567ba81 )
BitDefenderTrojan.GenericKD.43251965
K7GWTrojan ( 00567ba81 )
Cybereasonmalicious.83c773
F-ProtW32/MSIL_Troj.VE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.43251965
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
AlibabaTrojan:Win32/Maldoc.ali2000008
ViRobotTrojan.Win32.Z.Genkryptik.188928
TencentMsil.Trojan-banker.Clipbanker.Swlg
Ad-AwareTrojan.GenericKD.43251965
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.svste
TrendMicroTROJ_GEN.R015C0WEV20
McAfee-GW-EditionRDN/Generic.grp
FireEyeGeneric.mg.55acde4bde2328ac
EmsisoftTrojan.GenericKD.43251965 (B)
CyrenW32/MSIL_Troj.VE.gen!Eldorado
AviraTR/Kryptik.svste
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D293F8FD
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
MicrosoftTrojan:Win32/Vigorf.A
Acronissuspicious
McAfeeRDN/Generic.grp
MAXmalware (ai score=85)
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.ELMN
TrendMicro-HouseCallTROJ_GEN.R015C0WEV20
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
YandexTrojan.GenKryptik!
IkarusTrojan.Inject
FortinetMSIL/GenKryptik.EKRF!tr
BitDefenderThetaGen:NN.ZemsilF.34126.lm0@ayEeDUp
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Generic/Trojan.f6f

How to remove MSIL/GenKryptik.ELMN?

MSIL/GenKryptik.ELMN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment