Malware

About “MSIL/GenKryptik.EZON” infection

Malware Removal

The MSIL/GenKryptik.EZON is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.EZON virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects the presence of Wine emulator via function name
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a registry key
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/GenKryptik.EZON?


File Info:

crc32: ABE90DB1
md5: e4797ea53973363a3411d0c4bc6abc22
name: E4797EA53973363A3411D0C4BC6ABC22.mlw
sha1: 4f6be67a8d28578ae178796d732deec30b7cd587
sha256: 44b5433b69ab50ca347baa5c090d37cf7e348526f00b54fcd561144971f2fe4e
sha512: 7051060469d6d081dd03c7b8272ed8835ad11c5c7529a9b2e077897a126e3a9387013746c18ceebc6ce43105911be2d75ce770323def7a301dc4b0258ff3be31
ssdeep: 12288:xGZroYTVKf0dLeEI+7xzu20BUStywnbrX9Svh2xG:xGZrokKf01NxzN6lIyG
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2010
Assembly Version: 1.0.0.0
InternalName: StaticArrayInitTypeSize128.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Miracle
ProductVersion: 1.0.0.0
FileDescription: Miracle
OriginalFilename: StaticArrayInitTypeSize128.exe

MSIL/GenKryptik.EZON also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36016112
McAfeePWS-FCUF!E4797EA53973
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 00575b451 )
BitDefenderTrojan.GenericKD.36016112
K7GWTrojan ( 00575b451 )
CyrenW32/Trojan.SW.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
AlibabaTrojan:Win32/starter.ali1000139
ViRobotTrojan.Win32.Z.Ratx.727040
TencentMsil.Backdoor.Crysan.Ajlh
Ad-AwareTrojan.GenericKD.36016112
EmsisoftTrojan.GenericKD.36016112 (B)
ComodoMalware@#19pgf95hrn3ce
DrWebTrojan.PackedNET.498
TrendMicroTROJ_FRS.0NA103A721
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeGeneric.mg.e4797ea53973363a
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2258FF0
ZoneAlarmHEUR:Backdoor.MSIL.Crysan.gen
GDataMSIL.Malware.Injector.2Q4NEF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R362000
BitDefenderThetaGen:NN.ZemsilF.34742.Sm0@aqjYalp
ALYacSpyware.AgentTesla
MAXmalware (ai score=81)
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/GenKryptik.EZON
TrendMicro-HouseCallTROJ_FRS.0NA103A721
RisingTrojan.GenKryptik!8.AA55 (TFE:C:QSpyZk4jxTS)
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.ZEG!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Backdoor.c00

How to remove MSIL/GenKryptik.EZON?

MSIL/GenKryptik.EZON removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment