Malware

MSIL/Kryptik.YAO removal guide

Malware Removal

The MSIL/Kryptik.YAO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YAO virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.YAO?


File Info:

crc32: 17D11C6C
md5: 6754f10af6ecb656d75b2ef3d27a0e04
name: zxcvb.exe
sha1: 162fc936516aa07c626bf1422aa6e3e2e8ce128c
sha256: 483c603c9fb09c2e908d782f7e6f3f04e6e26b7eaaf8ac637733a4e4a32c80e7
sha512: bc21c31ffbdd8e3c199151b08aa3ad8dec493b961dc227d459bd0ef07f2e929039eadc984bf15a449a28e2a633ef4ac74e54ce4e70e94e645b4a24a25308d1d3
ssdeep: 12288:P8Z38wKZ/W1GU4a0cvbtnMdKttAsd3mnF4q/Zzg8wgoHmB5r:PuBKFUuwbtMdK3Asdy+q/Zk1gomB
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Lime_net.exe
FileVersion: 1.0.0.0
ProductName: VideoLAN
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: Lime_net.exe

MSIL/Kryptik.YAO also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43978918
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056f7431 )
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 0056f7431 )
Cybereasonmalicious.6516aa
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34298.Rm0@aKY8a!l
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R057C0PJ720
KasperskyHEUR:Trojan.MSIL.Chapak.gen
BitDefenderTrojan.GenericKD.43978918
Paloaltogeneric.ml
AegisLabTrojan.Multi.Generic.4!c
Ad-AwareTrojan.GenericKD.43978918
ComodoMalware@#1308myhnx7hmp
F-SecureHeuristic.HEUR/AGEN.1129534
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R057C0PJ720
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SentinelOneDFI – Malicious PE
SophosMal/Generic-S
IkarusTrojan.MSIL.Krypt
AviraHEUR/AGEN.1129534
MicrosoftTrojan:Win32/Ymacco.AA48
ArcabitTrojan.Generic.D29F10A6
CynetMalicious (score: 85)
VBA32TScope.Trojan.MSIL
ALYacTrojan.GenericKD.43978918
MalwarebytesTrojan.MalPack.MSIL
APEXMalicious
ESET-NOD32a variant of MSIL/Kryptik.YAO
YandexTrojan.GenKryptik!
MAXmalware (ai score=86)
eGambitUnsafe.AI_Score_99%
FortinetMSIL/GenKryptik.ESST!tr
MaxSecureTrojan.Malware.73757188.susgen
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM03.0.5D7F.Malware.Gen

How to remove MSIL/Kryptik.YAO?

MSIL/Kryptik.YAO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment