Malware

MSIL/GenKryptik.FFYZ removal

Malware Removal

The MSIL/GenKryptik.FFYZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FFYZ virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/GenKryptik.FFYZ?


File Info:

crc32: 340DEB98
md5: 2448a8c934504f16c73abfaad647cc32
name: 2448A8C934504F16C73ABFAAD647CC32.mlw
sha1: 4f4608ef2902f60a2a381c35245d7e65fd7c2637
sha256: 34c8eb272f1ac8adbf1070f02d23c18b5927eb24f7272fdda88e8875343a9b25
sha512: 3b2164f10a351c4efcd412b52b4567a11c9a081ed3aed6befe808b02333366076e0f4d0d8dced01ce402272714ac2f7303e78dd06440e9b972e434d9bc6b7262
ssdeep: 6144:JFcrRRh7PD0ODjzmsgHKm5MAcDB4iWU+mpHmjZ13vK9bt19mWXmfhQRkmtQpFwi:JF
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: All Rights Reserved
Assembly Version: 3.43.961.458
InternalName: xe55xe7exe88xe9exe88xe87xe57xe57xe88xe73xe8bxe8bxe6bxe56xe55xe5cxe6exe98.exe
FileVersion: 3.43.961.458
CompanyName: xe55xe7exe88xe9exe88xe87xe57xe57xe88xe73xe8bxe8bxe6bxe56xe55xe5cxe6exe98 Inc.
LegalTrademarks: xe55xe7exe88xe9exe88xe87xe57xe57xe88xe73xe8bxe8bxe6bxe56xe55xe5cxe6exe98
Comments: xe55xe7exe88xe9exe88xe87xe57xe57xe88xe73xe8bxe8bxe6bxe56xe55xe5cxe6exe98
ProductName: xe55xe7exe88xe9exe88xe87xe57xe57xe88xe73xe8bxe8bxe6bxe56xe55xe5cxe6exe98
ProductVersion: 3.43.961.458
FileDescription: xe55xe7exe88xe9exe88xe87xe57xe57xe88xe73xe8bxe8bxe6bxe56xe55xe5cxe6exe98
OriginalFilename: xe55xe7exe88xe9exe88xe87xe57xe57xe88xe73xe8bxe8bxe6bxe56xe55xe5cxe6exe98.exe
Translation: 0x0000 0x0514

MSIL/GenKryptik.FFYZ also known as:

K7AntiVirusTrojan ( 0057d4b71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.MSILHeracles.16670
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaBackdoor:MSIL/NanoBot.a4c3d3e1
K7GWTrojan ( 0057d4b71 )
Cybereasonmalicious.f2902f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FFYZ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Backdoor.MSIL.NanoBot.gen
BitDefenderGen:Variant.MSILHeracles.16670
ViRobotTrojan.Win32.Z.Genkryptik.3848704
MicroWorld-eScanGen:Variant.MSILHeracles.16670
Ad-AwareGen:Variant.MSILHeracles.16670
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34722.Qp0@aKeKo6ii
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0WEV21
McAfee-GW-EditionBehavesLike.Win32.Generic.wz
FireEyeGeneric.mg.2448a8c934504f16
EmsisoftGen:Variant.MSILHeracles.16670 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Nanocore.sqhlp
eGambitUnsafe.AI_Score_100%
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
ArcabitTrojan.MSILHeracles.D411E
AegisLabTrojan.MSIL.NanoBot.m!c
GDataGen:Variant.MSILHeracles.16670
AhnLab-V3Trojan/Win.Generic.C4504590
McAfeeGenericRXOS-MC!2448A8C93450
MAXmalware (ai score=86)
MalwarebytesTrojan.Crypt
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R06CC0WEV21
IkarusTrojan.Inject
FortinetMSIL/GenKryptik.FFYZ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove MSIL/GenKryptik.FFYZ?

MSIL/GenKryptik.FFYZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment