Malware

What is “MSIL/Kryptik.HES”?

Malware Removal

The MSIL/Kryptik.HES is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.HES virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Kryptik.HES?


File Info:

name: B1B39C53B4C286E23CEB.mlw
path: /opt/CAPEv2/storage/binaries/11ffabe9703a094b5184abe3b218648945785fab45d6fdfd5f0862b6f454dbaf
crc32: 13EECF6A
md5: b1b39c53b4c286e23ceb745802a1610c
sha1: 5f4b9ee0db3ff1f9d6b097f011ef96f0746d4e1a
sha256: 11ffabe9703a094b5184abe3b218648945785fab45d6fdfd5f0862b6f454dbaf
sha512: c1adda96a6536c563bdb9a32112bd0286516580771766c0a2ab37f133d1a82d8122cbb04dfc6cd299a7896b0b44e19962b3700d9bc956abdb1f7bcdf2c06b2b8
ssdeep: 96:UCoMUakG85sPc1LHuhQNRq436f9kD5zW+W1ulMk8wtaS0Bfkm4zNt:UCDCt5sPc1LCQrqBfSD1WT1A918fRa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2159C11666A7D22B5DBC527B813D102062291C94732972DDB98738FFAAF24F324DBDC
sha3_384: 45eac7c89a3e9838b00ea34256e644ac259765c6867fd098a4047f12cc4626c57820f49e0aa6d811d12c4e8ff5820f83
ep_bytes: ff250020400000000000000000000000
timestamp: 2074-05-01 21:24:07

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Force OP
FileVersion: 1.0.0.0
InternalName: Force OP.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Force OP.exe
ProductName: Force OP
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.HES also known as:

LionicTrojan.MSIL.Crypt.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.b1b39c53b4c286e2
McAfeeArtemis!B1B39C53B4C2
CylanceUnsafe
K7AntiVirusTrojan ( 004f760f1 )
K7GWTrojan ( 004f760f1 )
CrowdStrikewin/malicious_confidence_80% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.HES
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderTrojan.GenericKD.47593854
MicroWorld-eScanTrojan.GenericKD.47593854
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan.Crypt.Pezb
Ad-AwareTrojan.GenericKD.47593854
EmsisoftTrojan.GenericKD.47593854 (B)
DrWebTrojan.MulDrop19.13023
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
GDataMSIL.Backdoor.DCRat.7OGNL5
AviraHEUR/AGEN.1129968
MicrosoftTrojan:Win32/Wacatac.B!ml
BitDefenderThetaGen:NN.ZemsilF.34084.2m0@aGqePyc
ALYacTrojan.GenericKD.47593854
MAXmalware (ai score=83)
MalwarebytesTrojan.Downloader.Pastebin
TrendMicro-HouseCallTROJ_GEN.R002H0DL721
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.HES!tr
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.0db3ff
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Kryptik.HES?

MSIL/Kryptik.HES removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment