Malware

MSIL/Kryptik.NHU removal guide

Malware Removal

The MSIL/Kryptik.NHU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.NHU virus can do?

  • Unconventionial language used in binary resources: Finnish
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.NHU?


File Info:

crc32: 6C4FA94E
md5: ffa91fd016c426f2c1a779b48df1e7f5
name: records.exe
sha1: 048b238f003e47a9de661763852cba8d862a2d29
sha256: 4c69dd459ac738522e55da513004ec4f4406e6d50c523be31d211de65f6ec082
sha512: 29e0058f23c7a18abff059f0af56dc2d64f4f57d83411cf96a431cc817d6c899726b45b24ac0cdd4dd7066e9d38e264a99e0807887828ddd34554608c9816441
ssdeep: 3072:/7qEblM9vMr7gq4m+eDcAUK/7s5D1JrqdP+4hGb8ab3/vsLBA08F2b+0ExZ2A28:7CRWom3IKTs5brqh3pA0k2b+dZ88iV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

MSIL/Kryptik.NHU also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanTrojan.GenericKD.30437013
FireEyeGeneric.mg.ffa91fd016c426f2
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.30437013
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0052cbe21 )
BitDefenderTrojan.GenericKD.30437013
K7GWTrojan ( 0052cbe21 )
Cybereasonmalicious.016c42
TrendMicroTSPY_NEGASTEAL.LK
F-ProtW32/Msil.GGG
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.30437013
KasperskyHEUR:Trojan.MSIL.Generic
AlibabaVirTool:MSIL/Injector.0d4ec191
NANO-AntivirusTrojan.Win32.Kryptik.ezakhd
AegisLabTrojan.MSIL.Generic.4!c
Ad-AwareTrojan.GenericKD.30437013
SophosMal/Generic-S
ComodoTrojWare.MSIL.Androm.NHU@7mx3br
F-SecureHeuristic.HEUR/AGEN.1013214
DrWebTrojan.PWS.Stealer.19347
ZillyaTrojan.Kryptik.Win32.1397023
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.30437013 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.ITAC-5188
JiangminTrojan.MSIL.ixrn
AviraHEUR/AGEN.1013214
MAXmalware (ai score=100)
Antiy-AVLTrojan/MSIL.AGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1D06E95
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan.MSIL.Generic
MicrosoftVirTool:MSIL/Injector.TY!bit
AhnLab-V3Trojan/Win32.Injector.C2911430
McAfeePacked-FBC!FFA91FD016C4
VBA32TrojanPSW.Stealer
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.NHU
TrendMicro-HouseCallTSPY_NEGASTEAL.LK
YandexTrojan.Agent!UQKAq763qdA
IkarusTrojan.MSIL.Crypt
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.NHU!tr
WebrootW32.Trojan.GenKD
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.7c5

How to remove MSIL/Kryptik.NHU?

MSIL/Kryptik.NHU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment