Malware

MSIL/Kryptik.VCI (file analysis)

Malware Removal

The MSIL/Kryptik.VCI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.VCI virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.VCI?


File Info:

crc32: A0A4B60E
md5: 3855749aa61c5e99022ebf6286a9cc2b
name: vbc.exe
sha1: 6645ba34b99b1c1068c98a17dd345961206f0654
sha256: e9562206911b00e6f2479459c556bb24609d7151196792c31b9bba547e9c161c
sha512: 2c6cc7471114f2bc4832b8742e086588e17a646f9066a7a8cc3dd5703b238142bd4818a52a3dbbd8ff5152e2ec565d91c49ae256cc8fa44b23e567b0c36f00a5
ssdeep: 12288:lZpyXFfuD4G+0SLABGBTRauhCUw4mT9SM:Hpkqp+02sUw5T9
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: MethodRJLHZ
Assembly Version: 2.1.1.1
InternalName: MethodRJLHZ.exe
FileVersion: 2.1.1.1
LegalTrademarks: MethodRJLHZ
ProductName: MethodRJLHZ
ProductVersion: 2.1.1.1
FileDescription: MethodRJLHZ
OriginalFilename: MethodRJLHZ.exe

MSIL/Kryptik.VCI also known as:

MicroWorld-eScanTrojan.GenericKD.42863090
FireEyeGeneric.mg.3855749aa61c5e99
ALYacTrojan.GenericKD.42863090
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00562f641 )
BitDefenderTrojan.GenericKD.42863090
K7GWTrojan ( 00562f641 )
Cybereasonmalicious.4b99b1
TrendMicroTROJ_GEN.R01FC0PCL20
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
GDataTrojan.GenericKD.42863090
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojan:Win32/Kryptik.ali2000016
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareTrojan.GenericKD.42863090
EmsisoftTrojan.GenericKD.42863090 (B)
DrWebTrojan.PWS.Siggen2.45229
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.MSIL.Krypt
CyrenW32/MSIL_Kryptik.AJB.gen!Eldorado
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28E09F2
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!3855749AA61C
MalwarebytesSpyware.AgentTesla
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.VCI
TrendMicro-HouseCallTROJ_GEN.R01FC0PCL20
TencentMsil.Trojan-qqpass.Qqrob.Ljub
SentinelOneDFI – Malicious PE
FortinetMSIL/Kryptik.VBT!tr
BitDefenderThetaGen:NN.ZemsilF.34100.ym0@aqk9!Hi
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/Trojan.PSW.374

How to remove MSIL/Kryptik.VCI?

MSIL/Kryptik.VCI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment