Malware

MSIL/GenKryptik.FWLM malicious file

Malware Removal

The MSIL/GenKryptik.FWLM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.FWLM virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/GenKryptik.FWLM?


File Info:

name: 6FC2264616BDAAA97115.mlw
path: /opt/CAPEv2/storage/binaries/8fb75ebea42491eb03da94230afa9855bd3207d1d2d3d2cff843f497a5dc4b7b
crc32: 8762C379
md5: 6fc2264616bdaaa97115ebe30a54fbb8
sha1: 8f3cf8fa1b72b4b2822303a4f611aae766833385
sha256: 8fb75ebea42491eb03da94230afa9855bd3207d1d2d3d2cff843f497a5dc4b7b
sha512: 11b6545ad778dfdcac83312c4d9700a03a8bf460a590f4447d0f7081db6b7ca77926c0aa83525135064be2399f43fd0bc02c25d20077aaedd2f4025ab0477fe8
ssdeep: 6144:6kYtGLsyiUwz4ABDJfvRJXAek8GbhU+1aIQTdie:pYgqBFhM8OU+1aIQTdie
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FDC60A3C2CB9523BA169E6AD8FE58427F450E167F221D9349DD387854737C822ACB07E
sha3_384: e7f929fd647e0da79dce6c8000ff535fdd5c40a90d0826194aa78ae00d0bcc583ad99b3c49690886962c4dcc1dbf2f0d
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-06-23 11:49:10

Version Info:

Translation: 0x0000 0x04b0
FileDescription: tokyo_ghoul
FileVersion: 0.0.0.0
InternalName: houseboat.exe
LegalCopyright: Abdhshba | All Copyradsdvxzc
OriginalFilename: houseboat.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/GenKryptik.FWLM also known as:

LionicTrojan.MSIL.Stealer.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.50556467
FireEyeGeneric.mg.6fc2264616bdaaa9
ALYacTrojan.GenericKD.50556467
CylanceUnsafe
VIPRETrojan.GenericKD.50556467
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:MSIL/Stealer.d57598fe
K7GWTrojan ( 00594b241 )
K7AntiVirusTrojan ( 00594b241 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FWLM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefenderTrojan.GenericKD.50556467
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan.Genkryptik.Wtxq
Ad-AwareTrojan.GenericKD.50556467
EmsisoftTrojan.GenericKD.50556467 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Siggen18.17043
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
GDataWin32.Trojan-Stealer.Cordimik.0A3IJ3
AviraTR/Dropper.Gen
ArcabitTrojan.Generic.D3036E33
ZoneAlarmHEUR:Trojan-Spy.MSIL.Stealer.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.RedLine.C5179125
Acronissuspicious
McAfeeArtemis!6FC2264616BD
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R002H0AG122
RisingStealer.Agent!8.C2 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34742.@p3@aW9RDRp
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.a1b72b

How to remove MSIL/GenKryptik.FWLM?

MSIL/GenKryptik.FWLM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment