Malware

MSIL/GenKryptik.FHAA removal tips

Malware Removal

The MSIL/GenKryptik.FHAA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FHAA virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/GenKryptik.FHAA?


File Info:

crc32: 4D172D17
md5: 371a1cba0ebacad844efa26ac81010c0
name: 371A1CBA0EBACAD844EFA26AC81010C0.mlw
sha1: 70d86a88483fc65e82e2b72d8d7e9801b95fa9df
sha256: 20b056235f35b9c92264e185b04938f2dd6b6850ed4923541576df92914eaad4
sha512: 8ec25595da266f42534ff36e1e8a83410f7086f26139609bb27b6a280de0375dea7223ea47e8e81178fac854142384e9a66059cb7b5800c97e19199bb8d406e9
ssdeep: 6144:CQ8ma9Rn6LwfRSitNsNpStWbIWdmHE7eNtyIfcUT/IyXFlnp9wdB3/uAdp:MmuxuwY2sNIAUEA1jJf3T/IyXFln2t/
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 15.0.4454.1000
InternalName: zeeemiii.exe
FileVersion: 15.0.4454.1000
CompanyName: Microsoft Corporation
LegalTrademarks:
Comments: Microsoft PowerPoint
ProductName: Microsoft Office 2013
ProductVersion: 15.0.4454.1000
FileDescription: Microsoft PowerPoint
OriginalFilename: zeeemiii.exe

MSIL/GenKryptik.FHAA also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.540041
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:MSIL/GenKryptik.df39cc17
K7GWTrojan ( 0057eb3e1 )
CyrenW32/MSIL_Dropper.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FHAA
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.46552379
MicroWorld-eScanGen:Variant.Bulz.540041
Ad-AwareGen:Variant.Bulz.540041
BitDefenderThetaGen:NN.ZemsilF.34770.Am0@a80@e9e
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.371a1cba0ebacad8
EmsisoftTrojan.GenericKD.46552379 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Bulz.D83D89
AegisLabTrojan.Win32.Malicious.4!c
GDataTrojan.GenericKD.46552379
McAfeePWS-FCZZ!371A1CBA0EBA
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ABRS!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/GenKryptik.FHAA?

MSIL/GenKryptik.FHAA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment