Trojan

Should I remove “Trojan.MSIL.Crypt.hxha”?

Malware Removal

The Trojan.MSIL.Crypt.hxha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Crypt.hxha virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan.MSIL.Crypt.hxha?


File Info:

name: 4E924C79A5F9B832A250.mlw
path: /opt/CAPEv2/storage/binaries/853cd45f39a9ae0f2b8a6306fbd9a4b6bb8af59cd4caa18e70362476a8bbf821
crc32: 08F6790C
md5: 4e924c79a5f9b832a250ccbf75f22e01
sha1: cb2239a4fbdc8098f0c15d29708a4ae184e0e3c9
sha256: 853cd45f39a9ae0f2b8a6306fbd9a4b6bb8af59cd4caa18e70362476a8bbf821
sha512: e1c82a543b1858fb3323731f3952425eaf1c64a44e56c5d4715dc87c336972f60b6b01f162a3b6b933a8c990b6b8ca20c4f66ce99f1be5720583232a4d341742
ssdeep: 96:khW8omJCHuMPyNObHilH/S+8YG9zDdzW+Wn5+Er8BB9pUfgmquj+zNt:kkROMaNOga51BDZWTnLWB8f5M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F02F91AFBE89631E8774B31986651400777F61E9933EB6FA88D510B5EB33400BA2F71
sha3_384: b5a5545dcd65e82a9b2cd4b103e05d7b94dc781951cf8a20756b8b6da0e7400b8857ca1d6db19ea7d2a4e5f4e9a3f948
ep_bytes: ff250020400000000000000000000000
timestamp: 2064-05-18 09:12:12

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: ForceOP
FileVersion: 1.0.0.0
InternalName: ForceOP.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: ForceOP.exe
ProductName: ForceOP
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan.MSIL.Crypt.hxha also known as:

MicroWorld-eScanTrojan.GenericKD.47617931
FireEyeTrojan.GenericKD.47617931
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
K7AntiVirusTrojan-Downloader ( 0058ba2f1 )
AlibabaTrojan:MSIL/DropperX.9e9c4eeb
K7GWTrojan-Downloader ( 0058ba2f1 )
Cybereasonmalicious.4fbdc8
CyrenW32/MSIL_Kryptik.FIG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.DGL
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyTrojan.MSIL.Crypt.hxha
BitDefenderTrojan.GenericKD.47617931
TencentMsil.Trojan-downloader.Agent.Pgna
Ad-AwareTrojan.GenericKD.47617931
EmsisoftTrojan.GenericKD.47617931 (B)
TrendMicroTROJ_GEN.R002C0PLD21
McAfee-GW-EditionRDN/Generic Downloader.x
SophosMal/Generic-S
GDataTrojan.GenericKD.47617931
AviraHEUR/AGEN.1129962
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4840048
BitDefenderThetaGen:NN.ZemsilCO.34084.am0@aeDC33m
ALYacTrojan.GenericKD.47617931
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R002C0PLD21
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.CWW!tr.dldr
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan.MSIL.Crypt.hxha?

Trojan.MSIL.Crypt.hxha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment