Malware

MSIL/GenKryptik.EWHB removal guide

Malware Removal

The MSIL/GenKryptik.EWHB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.EWHB virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/GenKryptik.EWHB?


File Info:

name: 1684DB53FA6AF035B27C.mlw
path: /opt/CAPEv2/storage/binaries/50af86d014af8073b00898f45e0a3f5edcb7de5b4ec3bbddfd8a75f1d069c2a2
crc32: BB5082B4
md5: 1684db53fa6af035b27c2b1b1000b60c
sha1: b4638ed0b1d9898d976c1809345271c0f4bba9e3
sha256: 50af86d014af8073b00898f45e0a3f5edcb7de5b4ec3bbddfd8a75f1d069c2a2
sha512: 96dcb58430eab3a7e566943cc479f2b1e3d6c4b55cf2667df418ee287d9c8bb157d4e04bba413277b06101397f79722010bdac1886a27c3600096bc66ca60929
ssdeep: 384:Q+CEsC/vfnvhm99rLozmeLIwOxnLa3/AbmF+yA8HsPTWInfVL4yber:Ro99PozNLEgAlyALPTWCB4Ca
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B5848D716E47A099D4FE47F1391AA2038FEE6DED18B8C356213033390EF53AD4A56272
sha3_384: 80eed35bbf7f512b20c8d2d990484871c71188fea09a71c8723c2f6008e15357846226da3c4282e9b1b09d8d4fb677b6
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-13 09:28:51

Version Info:

Translation: 0x0000 0x04b0
Comments: Creative Cloud Desktop
CompanyName: Adobe Inc.
FileDescription: Creative Cloud Desktop
FileVersion: 5.3.1.470
InternalName: local.exe
LegalCopyright: © 2019-2020 Adobe. All rights reserved.
LegalTrademarks:
OriginalFilename: local.exe
ProductName: Creative Cloud Desktop
ProductVersion: 5.3.1.470
Assembly Version: 5.3.1.470

MSIL/GenKryptik.EWHB also known as:

BkavW32.AIDetectNet.01
FireEyeGeneric.mg.1684db53fa6af035
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/MSIL_Agent.DMO.gen!Eldorado
SymantecMSIL.Downloader!gen7
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.EWHB
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-Spy.MSIL.Noon.gen
AvastWin32:RATX-gen [Trj]
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZemsilF.34786.xm0@aWnJQ9n
MalwarebytesTrojan.Downloader.MSIL.Generic
RisingMalware.Obfus/MSIL@AI.91 (RDM.MSIL:Ybj8nJtizylFgNTsuA5WMw)
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.MNX!tr.dldr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.3fa6af

How to remove MSIL/GenKryptik.EWHB?

MSIL/GenKryptik.EWHB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment