Malware

About “MSIL/GenKryptik.FHOR” infection

Malware Removal

The MSIL/GenKryptik.FHOR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FHOR virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/GenKryptik.FHOR?


File Info:

crc32: 57362BE9
md5: 2162abcdcff5c40d0b0e63362e9707a8
name: 2162ABCDCFF5C40D0B0E63362E9707A8.mlw
sha1: c723cbe108f1fb3a926a7539cd574fb5d0336ac0
sha256: 8fd4cf94ee8683475a5fa775b37afeaeef36e4791fd1e3ecfde74cfaaf498106
sha512: 29a613d8f680ec2d65d72902a128aecf05b2505bbdee2eaa1b81046bb9b5f9f7c74483f3af746c39b576e2f5399a14cc56550848e5e36c92ca37621dd6b28ffb
ssdeep: 12288:WDEvp3rgo+V+x8SUiQStZizZxF4dCqaCRXf3dWmYiXglxnHULYX+2jnkvwF4VJF:YmEl+XNuxinXf3dWmYiXglZs6FGz7p
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Setiono 2011
Assembly Version: 1.7.0.3
InternalName: SurrogateK.exe
FileVersion: 1.7.0.3
CompanyName: Setiono
LegalTrademarks:
Comments: GameDots
ProductName: GameDotS
ProductVersion: 1.7.0.3
FileDescription:
OriginalFilename: SurrogateK.exe

MSIL/GenKryptik.FHOR also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.108f1f
CyrenW32/MSIL_Kryptik.DMC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FHOR
APEXMalicious
KasperskyVHO:Email-Worm.MSIL.LovGate.gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34796.!m0@aONtYKb
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.2162abcdcff5c40d
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/AgentTesla!ml
MalwarebytesMachineLearning/Anomalous.95%
MaxSecureTrojan.Malware.300983.susgen
Qihoo-360HEUR/QVM03.0.9A5B.Malware.Gen

How to remove MSIL/GenKryptik.FHOR?

MSIL/GenKryptik.FHOR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment