Malware

About “MSIL/GenKryptik.EWFT” infection

Malware Removal

The MSIL/GenKryptik.EWFT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.EWFT virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine MSIL/GenKryptik.EWFT?


File Info:

crc32: 18E19101
md5: e9f04bbd5428422643901bbdbe8bd3bf
name: E9F04BBD5428422643901BBDBE8BD3BF.mlw
sha1: 3c33f938cd57d8ac2433068252c2330d1ce510b9
sha256: d365a8242fb16dd10dc6a80f41740c4b96d60090621d7f2c67d64a695fb9991a
sha512: 76785cc76010d3180f1bd8fa57f6e1e6dd7a53b78f192338c30d833282737002094b78d95c04ebda7d62a4d372bd2dfde2c68859b344d34e4190932adc94f833
ssdeep: 49152:HNQvTSf5ajgIBs9cyKLlwXmHzZKuVCvTSf5ajgIBs9cyK0:SWfo3MKBAmHzguVWWfo3MK0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 SpiceBrains.com
InternalName: Instant Eyedropper
FileVersion: 1.9.1.0
CompanyName: SpiceBrains
ProductName: Instant Eyedropper
ProductVersion: 1.9.1
FileDescription: Color detection tool
OriginalFilename: instanteyedropper.exe
Translation: 0x0409 0x04e4

MSIL/GenKryptik.EWFT also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35560280
McAfeeArtemis!E9F04BBD5428
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 00563cb01 )
BitDefenderTrojan.GenericKD.35560280
K7GWTrojan ( 00563cb01 )
ArcabitTrojan.Generic.D21E9B58
BitDefenderThetaGen:NN.ZemsilF.34670.@x0@ai2faxfi
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Kryptik.ali2000016
Ad-AwareTrojan.GenericKD.35560280
EmsisoftTrojan.GenericKD.35560280 (B)
DrWebTrojan.Siggen11.54401
TrendMicroTrojan.MSIL.MALREP.THLOEBO
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.e9f04bbd54284226
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=87)
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.35560280
ALYacTrojan.GenericKD.35560280
ESET-NOD32a variant of MSIL/GenKryptik.EWFT
TrendMicro-HouseCallTrojan.MSIL.MALREP.THLOEBO
IkarusTrojan.MSIL.Vmprotect
FortinetMSIL/GenKryptik.EWFT!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove MSIL/GenKryptik.EWFT?

MSIL/GenKryptik.EWFT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment