Trojan

Trojan.MSIL.Khalesi removal instruction

Malware Removal

The Trojan.MSIL.Khalesi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Khalesi virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan.MSIL.Khalesi?


File Info:

name: DAAB72DB3DF268A01EB7.mlw
path: /opt/CAPEv2/storage/binaries/3bc34f83dcd23ae94c26b98209b5971a569012a3c0905fca16b26e355ccb652f
crc32: FC916F75
md5: daab72db3df268a01eb7338f6f6a0ae3
sha1: 7f537e7c05f44c87161d809369d341393402eb33
sha256: 3bc34f83dcd23ae94c26b98209b5971a569012a3c0905fca16b26e355ccb652f
sha512: c299b0d8221642e101cba562b39aae9fb9c888847c04adc0ff580e32cf4fb95610b24d45a89d7390f38c9554f5110badf8d7535f933ad74d7ea1fbcb9a8551bb
ssdeep: 384:/goHplv3Pigdn5b8H5DiQ/npos9UKxCchYcXSVzQ3c:BHpxlGZWQV9UKxDhYcXSVz+c
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F4621A07B3B84271E53AC27B2D3353C29676FB16691A479F708E504E2F6863077237A2
sha3_384: e29b0ee2284ccdaf91ecac5e9b30afeec2bae41b58cc263fac8a7f96fe299a3aaaa246d19787f982cc94ee5acb4b664a
ep_bytes: ff2500204000308209f9020103308209
timestamp: 2093-06-07 12:32:40

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: HaoCrack
FileVersion: 1.0.0.0
InternalName: HaoCrack.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: HaoCrack.exe
ProductName: HaoCrack
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan.MSIL.Khalesi also known as:

LionicTrojan.MSIL.Khalesi.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.38854673
FireEyeTrojan.GenericKD.38854673
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.38854673
CylanceUnsafe
ZillyaTrojan.Khalesi.Win32.60993
SangforTrojan.Win32.GenericKD.38854673
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Trojan.WHWF-2432
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Khalesi.gen
BitDefenderTrojan.GenericKD.38854673
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Trojan.Khalesi.Wtxj
Ad-AwareTrojan.GenericKD.38854673
EmsisoftTrojan.GenericKD.38854673 (B)
ComodoApplicUnwnt@#23zq8ao3fe0jm
TrendMicroTROJ_GEN.R002C0PB522
McAfee-GW-EditionRDN/Generic.rp
SophosCrackTool (PUA)
GDataTrojan.GenericKD.38854673
JiangminTrojan.MSIL.amffv
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3523DBA
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D250E011
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4950512
McAfeeRDN/Generic.rp
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesCrackTool.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0PB522
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.74000543.susgen

How to remove Trojan.MSIL.Khalesi?

Trojan.MSIL.Khalesi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment