Malware

Should I remove “MSIL/GenKryptik.FGFS”?

Malware Removal

The MSIL/GenKryptik.FGFS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FGFS virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/GenKryptik.FGFS?


File Info:

crc32: E0B98001
md5: c89c05d0f2853fa30b535aa2544006e5
name: C89C05D0F2853FA30B535AA2544006E5.mlw
sha1: 2e3a6adc296d26732a3c61ac761052b8793f7da0
sha256: b2ec2e506bc9741873e39cc6fdc07802a1180136657582ae807d5f6112cfc02a
sha512: ba3ece975821799aee081c04ed73027c4d389ad97b237e2f65d454181922ebac7ecacf08783046a3e51c67cd283118ba57ef6f6bb6f9918f284084ebae1d3378
ssdeep: 24576:4ZBPnHeenJNTfyZbKldRTBeRmZPpYKH2k4mLM:4BeWTfyZbqdR1eCYQ4
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015
Assembly Version: 1.0.0.0
InternalName: PH8v.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: WinFormsFBWintask
ProductVersion: 1.0.0.0
FileDescription: WinFormsFBWintask
OriginalFilename: PH8v.exe

MSIL/GenKryptik.FGFS also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.Inject4.12332
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.MSIL
ALYacTrojan.GenericKD.37038294
SangforInfostealer.MSIL.Agensla.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/starter.ali1000139
K7GWRiskware ( 0040eff71 )
CyrenW32/MSIL_Kryptik.ELQ.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/GenKryptik.FGFS
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKD.37038294
NANO-AntivirusTrojan.Win32.Agensla.iwcbsr
ViRobotTrojan.Win32.Z.Malpack.1245184
MicroWorld-eScanTrojan.GenericKD.37038294
Ad-AwareTrojan.GenericKD.37038294
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.gbbuc@0
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.MSIL.NEGASTEAL.SMG
McAfee-GW-EditionPWS-FCXD!C89C05D0F285
FireEyeTrojan.GenericKD.37038294
EmsisoftTrojan.GenericKD.37038294 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/AD.Nanocore.eaknt
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.BFF!MTB
ArcabitTrojan.Generic.D23528D6
GDataMSIL.Trojan.PSE.ZTH9OG
AhnLab-V3Trojan/Win.AgentTesla.C4514382
McAfeePWS-FCXD!C89C05D0F285
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.ADC.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H01F421
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Malicious_Behavior.SBX
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/GenKryptik.FGFS?

MSIL/GenKryptik.FGFS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment