Malware

MSIL/GenKryptik.GNNA removal

Malware Removal

The MSIL/GenKryptik.GNNA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/GenKryptik.GNNA virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine MSIL/GenKryptik.GNNA?


File Info:

name: D3789609E4C88F02672A.mlw
path: /opt/CAPEv2/storage/binaries/dc71cf5b8e5be7698ac8b2be98cc06a953f47dcdd3507117b29e7ac85a40a1db
crc32: CFAEA41E
md5: d3789609e4c88f02672a03cef863556c
sha1: d28847692f09182b5f99fde316208bdb941a7b97
sha256: dc71cf5b8e5be7698ac8b2be98cc06a953f47dcdd3507117b29e7ac85a40a1db
sha512: d98c5f836817be643122ba1a32e27327d7128d454325a804bf077f4a7561f910bf45b16dc3b2abd73a56bcd7ffecfdb2776efee126162c577277af344d129464
ssdeep: 12288:YRfxOJPJVWlVUdxVO7+/aHlCRkfcszvk5tuqY22JNtRhyk0vRjQ+sggGxLHJ/X:CONGQd+C/RRk5zk50qoJm2w3LHFX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111D412A037EE4B67E17A17FD3932005503B1B98E36A1D7AE2E9915EA0873F845740B1B
sha3_384: 6a9ed8672d341843159d7b8364843d427b9549744e6800425952047ea9bdbe51c01f833df71e34100f11adbc3955bd99
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-09-06 00:36:28

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: JlkB.exe
LegalCopyright:
OriginalFilename: JlkB.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

MSIL/GenKryptik.GNNA also known as:

BkavW32.Common.E5263B0B
LionicTrojan.Win32.SnakeLogger.4!c
MicroWorld-eScanTrojan.GenericKD.69148106
FireEyeGeneric.mg.d3789609e4c88f02
SkyhighBehavesLike.Win32.Generic.jc
ALYacTrojan.GenericKD.69148106
MalwarebytesTrojan.Crypt.MSIL.Generic
VIPRETrojan.GenericKD.69148106
SangforSuspicious.Win32.Save.a
AlibabaTrojanSpy:MSIL/Androm.b18a560e
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MSIL_Heur.A
SymantecScr.Malcode!gdn34
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/GenKryptik.GNNA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.MSIL.SnakeLogger.gen
BitDefenderTrojan.GenericKD.69148106
NANO-AntivirusTrojan.Win32.SnakeLogger.kanblg
AvastWin32:PWSX-gen [Trj]
EmsisoftTrojan.GenericKD.69148106 (B)
F-SecureTrojan.TR/AD.Nekark.lsagq
DrWebTrojan.PackedNET.738
TrendMicroTrojanSpy.Win32.NEGASTEAL.YXDIFZ
SophosTroj/Krypt-AAY
IkarusTrojan.MSIL.Inject
GDataTrojan.GenericKD.69148106
GoogleDetected
AviraTR/AD.Nekark.lsagq
Antiy-AVLTrojan/MSIL.GenKryptik
ArcabitTrojan.Generic.D41F1DCA
ZoneAlarmHEUR:Trojan-Spy.MSIL.SnakeLogger.gen
MicrosoftTrojan:MSIL/Androm.AMAA!MTB
VaristW32/MSIL_Agent.GJM.gen!Eldorado
AhnLab-V3Trojan/Win.MSIL.C5482249
McAfeeTrojan-FVRK!D3789609E4C8
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.NEGASTEAL.YXDIFZ
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:URXixmqEuJQLqobTBmIt5w)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AJOF!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove MSIL/GenKryptik.GNNA?

MSIL/GenKryptik.GNNA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment