Malware

What is “MSIL/Kryptik.YIH”?

Malware Removal

The MSIL/Kryptik.YIH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YIH virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.YIH?


File Info:

crc32: F0D28D73
md5: 8110de48ceebd693772c11cf5ddcdbbc
name: upload_file
sha1: 55a04ff7046f48f7c9e47705f331acf650248a88
sha256: 59e6e153c09dcb84b6b55416a9168208c49d376eb9ce8b7b7d27b81937128a3c
sha512: 1051618e6ac7e3b2d8290353d34835426b320f2667891172268d57382ce7f96746559e4fbd60735a1c41efc110cddd55d48c4630d11483c1768da59997e0a369
ssdeep: 12288:u1wM4WQ/c2VzMGe5i4ewk2nA+gCPV9w4hHUc:PW4jNRejk2nZn7Sc
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2003 - 2020
Assembly Version: 0.0.0.0
InternalName: 3601997.exe
FileVersion: 6.10.13.16
CompanyName: 8z-@0nc{93e&?
Comments: Rygoxizhofykovoxafuro
ProductName: Duhaevowoshute
ProductVersion: 6.10.13.16
FileDescription: Duhaevowoshute
OriginalFilename: 3601997.exe

MSIL/Kryptik.YIH also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44159852
FireEyeGeneric.mg.8110de48ceebd693
Qihoo-360Generic/HEUR/QVM03.0.C5BC.Malware.Gen
McAfeePWS-FCQR!8110DE48CEEB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 00571b5e1 )
BitDefenderTrojan.GenericKD.44159852
K7GWTrojan ( 00571b5e1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/MSIL_Kryptik.BZH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaBackdoor:MSIL/Androm.2cf8479f
ViRobotTrojan.Win32.Z.Highconfidence.466944.A
Ad-AwareTrojan.GenericKD.44159852
EmsisoftTrojan.GenericKD.44159852 (B)
F-SecureTrojan.TR/Kryptik.wquzk
InvinceaMal/Generic-R + Troj/MSIL-QAN
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosTroj/MSIL-QAN
SentinelOneDFI – Malicious PE
AviraTR/Kryptik.wquzk
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.D5!ml
ArcabitTrojan.Generic.D2A1D36C
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.GenericKD.44159852
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4210666
BitDefenderThetaGen:NN.ZemsilF.34590.Cm0@aSFbnhc
ALYacTrojan.GenericKD.44159852
MalwarebytesTrojan.Crypt.MSIL
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.YIH
TencentMsil.Backdoor.Androm.Dwiq
IkarusTrojan.MSIL.Crypt
eGambitUnsafe.AI_Score_58%
FortinetMSIL/Kryptik.YID!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.7046f4
AvastWin32:MalwareX-gen [Trj]
MaxSecureTrojan.Malware.300983.susgen

How to remove MSIL/Kryptik.YIH?

MSIL/Kryptik.YIH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment