Malware

MSIL/GenKryptik.FHLO information

Malware Removal

The MSIL/GenKryptik.FHLO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FHLO virus can do?

  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine MSIL/GenKryptik.FHLO?


File Info:

name: C6126112507B31F38A45.mlw
path: /opt/CAPEv2/storage/binaries/fffc8590b90d44edfc62bfce6b3768a8f83464f779aa20dae26ef2e323421ff0
crc32: 8BBEC9E5
md5: c6126112507b31f38a453a64e026d19f
sha1: 5525c03ba090d8c8229890e168680a8dce892848
sha256: fffc8590b90d44edfc62bfce6b3768a8f83464f779aa20dae26ef2e323421ff0
sha512: d639775ea1be6666a6123fde706563d99c763d8fd090639ecac04a9ff5f9f05191ba46f8896e14c002b29d7c608b73d880acb72dddb9d8d8ae9281a5762c4356
ssdeep: 6144:6K5A5QPBEl9PK5A5QPBEl9PK5A5QPBEl9:6F0arPF0arPF0ar
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T12984050776C85758C8206AB184FB187503D2AED71773EB95FF4967DE0E103A6DE82B0A
sha3_384: e1693500e94bb19ae5e4c7685e3ce873736654a5a2d0d3cac1e543d669e833944e88ac5f1a7230b8f2a29473807774a3
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-08-02 06:36:46

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: 134.exe
LegalCopyright:
OriginalFilename: 134.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/GenKryptik.FHLO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47347294
FireEyeGeneric.mg.c6126112507b31f3
ALYacTrojan.GenericKD.47347294
CylanceUnsafe
K7AntiVirusTrojan ( 0057f43f1 )
K7GWTrojan ( 0057f43f1 )
Cybereasonmalicious.ba090d
ESET-NOD32a variant of MSIL/GenKryptik.FHLO
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Miner.gen
BitDefenderTrojan.GenericKD.47347294
AvastWin64:Trojan-gen
Ad-AwareTrojan.GenericKD.47347294
SophosML/PE-A
DrWebTrojan.DownloaderNET.25
McAfee-GW-EditionBehavesLike.Win64.Generic.fh
EmsisoftTrojan.GenericKD.47347294 (B)
IkarusTrojan-Dropper.MSIL.Agent
GDataTrojan.GenericKD.47347294
AviraHEUR/AGEN.1139790
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4530727
MAXmalware (ai score=84)
VBA32Trojan.MSIL.Miner
MalwarebytesBackdoor.Agent.PGen
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
FortinetMSIL/Kryptik.ACBQ!tr
AVGWin64:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MSIL/GenKryptik.FHLO?

MSIL/GenKryptik.FHLO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment