Malware

MSIL/GenKryptik.EUVI malicious file

Malware Removal

The MSIL/GenKryptik.EUVI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.EUVI virus can do?

  • Presents an Authenticode digital signature
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/GenKryptik.EUVI?


File Info:

crc32: 78259E39
md5: 33a4a5d7e53055d3a03d57d5e4264995
name: Baumer RFQ 532096__pdf.exe
sha1: 5211691e449023a935082445619b36f9084bd5f0
sha256: f0f5332559c5b4423f52173fbbde05923b236a0d32c97ad858b25621d5bf117a
sha512: f41e26d4af441fb7c021cd5e37e1f53c03bd351a33b76f95a6f60d8c4c34d0cdc666db28050600f931835eedaac3362828b226bb8b7a34e067c08b5dac653bf7
ssdeep: 6144:Ubqv96qwHLQoXaZMrkY740THgJyCc1zgywW4o+1+WnWJmeElcMM7+Z3w8sTAZjv7:75VV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 16.0.0.0
InternalName: VSPerfAspNetCmd.exe
FileVersion: 16.0.30013.169
CompanyName: Microsoft Corporation
Comments: VSPerfAspNetCmd.exe
ProductName: Microsoftxae Visual Studioxae
ProductVersion: 16.0.30013.169
FileDescription: VSPerfAspNetCmd.exe
OriginalFilename: VSPerfAspNetCmd.exe

MSIL/GenKryptik.EUVI also known as:

MicroWorld-eScanTrojan.GenericKD.34870308
FireEyeTrojan.GenericKD.34870308
McAfeeArtemis!33A4A5D7E530
CylanceUnsafe
K7AntiVirusTrojan ( 00571a991 )
BitDefenderTrojan.GenericKD.34870308
K7GWTrojan ( 00571a991 )
SymantecTrojan Horse
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
AlibabaBackdoor:MSIL/GenKryptik.6b13d975
Ad-AwareTrojan.GenericKD.34870308
ComodoMalware@#3ka1rawcerr4
DrWebTrojan.Siggen10.41272
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionRemcos-rat.a
SophosMal/Generic-S
IkarusTrojan.MSIL.Krypt
JiangminTrojan.PSW.MSIL.atjn
AviraTR/Kryptik.imuhl
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Ymacco.AAF0
ArcabitTrojan.Generic.D2141424
ZoneAlarmHEUR:Backdoor.MSIL.Remcos.gen
GDataTrojan.GenericKD.34870308
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.EUVI
TencentWin32.Trojan.Falsesign.Ljua
FortinetMalicious_Behavior.SB
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Backdoor.23a

How to remove MSIL/GenKryptik.EUVI?

MSIL/GenKryptik.EUVI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment