Malware

About “MSIL/GenKryptik.EVXA” infection

Malware Removal

The MSIL/GenKryptik.EVXA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.EVXA virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/GenKryptik.EVXA?


File Info:

crc32: 1808DC09
md5: 66cf0d4e1f5bcba3d37e4a13b8601d92
name: 66CF0D4E1F5BCBA3D37E4A13B8601D92.mlw
sha1: 5da09dfc283327b4cb0a32dc0f0a9730a8c923f5
sha256: b9cdbda14ecde37f1914367130d2aecfd55485dddda99878de9702d53817e821
sha512: e8511c889767493cc48687c9f5822952523abefc97a4e2b3389a8b98b0353e3f65c67df87ad41342007237f7d46e40df32484bc3ca48b543002ecbce275cff9a
ssdeep: 12288:sbfA4cX8uiW40HcFn8xR9fZbGIY3m+D+t8bMsa2iSo:saX8uiHd8j9xiu+D+F2iZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2014 - 2020
Assembly Version: 1.0.0.0
InternalName: DQab.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Fault Tree
ProductVersion: 1.0.0.0
FileDescription: Fault Tree
OriginalFilename: DQab.exe

MSIL/GenKryptik.EVXA also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.424
MicroWorld-eScanTrojan.GenericKDZ.71256
FireEyeGeneric.mg.66cf0d4e1f5bcba3
ALYacTrojan.GenericKDZ.71256
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKDZ.71256
Cybereasonmalicious.c28332
BitDefenderThetaGen:NN.ZemsilF.34634.Jm0@a8au9ao
CyrenW32/MSIL_Kryptik.CCE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
Ad-AwareTrojan.GenericKDZ.71256
SophosTroj/Kryptik-NX
F-SecureTrojan.TR/AD.AgentTesla.iagfw
InvinceaTroj/Kryptik-NX
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftTrojan.GenericKDZ.71256 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.axwk
MaxSecureWin.MxResIcn.Heur.Gen
AviraTR/AD.AgentTesla.iagfw
MicrosoftTrojan:MSIL/Agensla.GG!MTB
ArcabitTrojan.Generic.D11658
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataMSIL.Trojan-Stealer.AgentTesla.NU0HDF
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4222786
McAfeePWS-FCSU!66CF0D4E1F5B
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt
PandaTrj/GdSda.A
ZonerTrojan.Win32.97915
ESET-NOD32a variant of MSIL/GenKryptik.EVXA
RisingTrojan.GenKryptik!8.AA55 (TFE:C:KHM1MWB2hEL)
IkarusTrojan.MSI.Inject
FortinetMSIL/GenKryptik.EWBH!tr
AVGWin32:MalwareX-gen [Trj]

How to remove MSIL/GenKryptik.EVXA?

MSIL/GenKryptik.EVXA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment