Malware

MSIL/GenKryptik.GNDF (file analysis)

Malware Removal

The MSIL/GenKryptik.GNDF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.GNDF virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/GenKryptik.GNDF?


File Info:

name: 4FB44CE11BBCDCFDB02F.mlw
path: /opt/CAPEv2/storage/binaries/41b09d1202db4dfb8db58a5cd9f68953db7d7547fab1c76234b3dd95cfac318e
crc32: 337932A9
md5: 4fb44ce11bbcdcfdb02f0a54f01ce4d6
sha1: 5fba539b0b34251e9d191d32143fe515ccd550a4
sha256: 41b09d1202db4dfb8db58a5cd9f68953db7d7547fab1c76234b3dd95cfac318e
sha512: ec79d2cf2ebecb2d7dea179600dc488abd7a5327640a3062ba27e7e4bce23045dd9a5e5f2165aa042346db2adbd003ea393a5c2fc4d9334e87dc93ab6557b681
ssdeep: 12288:3bqwi/iWsjsikxh/fY5L9n+hfva4v0gKq05v69fTNPZku:LqwiiWriQgHUn41+TH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BD4237C767C5B28D43AA7F70C69109A03F7777A06A2F3981C51E4FB64A9B018760E23
sha3_384: 0b682e17d6c62762a91697d01d162326059cfd5b1ea59dd1ea179e0bd91a541aa1538fadcc62da773626cb4509793d66
ep_bytes: ff250020400000000000000000000000
timestamp: 2065-03-11 01:54:47

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: QuanlyKho
FileVersion: 1.0.0.0
InternalName: Ncyn.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: Ncyn.exe
ProductName: QuanlyKho
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/GenKryptik.GNDF also known as:

BkavW32.Common.1E497B8D
LionicTrojan.Win32.Noon.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68906319
FireEyeTrojan.GenericKD.68906319
ALYacTrojan.GenericKD.68906319
MalwarebytesTrojan.MalPack.PNG.Generic
SangforSpyware.Msil.Kryptik.Vxi1
K7AntiVirusTrojan ( 005aa4171 )
K7GWTrojan ( 005aa4171 )
VirITTrojan.Win32.MSIL_Heur.A
CyrenW32/MSIL_Agent.FPI.gen!Eldorado
SymantecScr.Malcode!gdn34
ESET-NOD32a variant of MSIL/GenKryptik.GNDF
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Noon.gen
BitDefenderTrojan.GenericKD.68906319
NANO-AntivirusTrojan.Win32.Noon.jyxsbd
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan-Spy.Noon.Vmhl
EmsisoftTrojan.GenericKD.68906319 (B)
DrWebTrojan.Siggen21.21469
VIPRETrojan.GenericKD.68906319
TrendMicroTrojanSpy.MSIL.NOON.USPAXHP23
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
Trapminesuspicious.low.ml.score
SophosTroj/Krypt-ABH
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.68906319
WebrootW32.Trojan.Gen
GoogleDetected
XcitiumMalware@#1etr381vylg7y
ZoneAlarmHEUR:Trojan-Spy.MSIL.Noon.gen
MicrosoftTrojan:Win32/Leonem
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.PWSX-gen.C5475580
Acronissuspicious
McAfeeTrojan-FVQG!4FB44CE11BBC
MAXmalware (ai score=83)
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.NOON.USPAXHP23
RisingMalware.Obfus/MSIL@AI.80 (RDM.MSIL2:fzLO9MJM4UgR1+PCcWP/2w)
YandexTrojan.Igent.b0Jd9y.13
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.73691310.susgen
FortinetMSIL/GenKryptik.PWSX!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/GenKryptik.GNDF?

MSIL/GenKryptik.GNDF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment