Malware

What is “MSIL/Kryptik.YHD”?

Malware Removal

The MSIL/Kryptik.YHD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YHD virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.YHD?


File Info:

crc32: 0FB351C0
md5: 4dfe2fe7b3c818fdbfd5c47e7875f596
name: upload_file
sha1: 3dc34b020d2e03cd7651d63dec68ca0d1c35838b
sha256: 382cb836252147bd203a592b73db28024cf9aa7a78abcca57ee472362bf8cdfb
sha512: 03b7bdb7d127f9d1ce745a6e836d50d895f1dbcbc0c536f971ad37a5dbfe1aafe67d3daf9b7ecc259233c13fccb539ab8f78afb0004bf2d3708ee7fb8fcfa8b2
ssdeep: 3072:mxmYKXoV96iXNXr2/OLHaXXR4Xotjq6VsimZ3xNtxbb+IonONL1N111111405kK:mAYogLEax
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: (c) 2000-2020 Martin Prikryl
Assembly Version: 5.17.8.10803
InternalName: main.exe
FileVersion: 5.17.8.10803
CompanyName: Martin Prikryl
Comments: Setup for WinSCP 5.17.8 (SFTP, FTP, WebDAV and SCP client)
ProductName: WinSCP
ProductVersion: 5.17.8.10803
FileDescription: Setup for WinSCP 5.17.8 (SFTP, FTP, WebDAV and SCP client)
OriginalFilename: main.exe

MSIL/Kryptik.YHD also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34834422
FireEyeGeneric.mg.4dfe2fe7b3c818fd
McAfeeRDN/Generic.rp
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005718d81 )
BitDefenderTrojan.GenericKD.34834422
K7GWTrojan ( 005718d81 )
Cybereasonmalicious.20d2e0
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
AlibabaTrojanPSW:MSIL/Kryptik.8238f6d1
ViRobotTrojan.Win32.Z.Wacatac.832000
AegisLabTrojan.Multi.Generic.4!c
Ad-AwareTrojan.GenericKD.34834422
F-SecureTrojan.TR/AD.AgentTesla.faqth
DrWebBackDoor.SpyBotNET.25
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.34834422 (B)
IkarusTrojan.Win32.CoinMiner
AviraTR/AD.AgentTesla.faqth
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.D3!ml
ArcabitTrojan.Generic.D21387F6
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataMSIL.Trojan-Stealer.AgentTesla.DL9D38
CynetMalicious (score: 90)
BitDefenderThetaGen:NN.ZemsilF.34570.Ym0@aSK5uGl
MalwarebytesTrojan.Injector
ESET-NOD32a variant of MSIL/Kryptik.YHD
TrendMicro-HouseCallTROJ_GEN.F0D1C00JK20
TencentMsil.Trojan-qqpass.Qqrob.Piks
SentinelOneDFI – Malicious PE
FortinetMSIL/Kryptik.YEX!tr
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)

How to remove MSIL/Kryptik.YHD?

MSIL/Kryptik.YHD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment