Malware

MSIL/Kryptik.YKW malicious file

Malware Removal

The MSIL/Kryptik.YKW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YKW virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.YKW?


File Info:

crc32: 67BFAA7E
md5: 00ede4200f01ac7f9bf31946f27c56f6
name: upload_file
sha1: 56a1b25d1938e5f4fd70c577828a2e31050caa24
sha256: 15cbeb36e88d436a2364f59bc23cf3b3ffc7dda567fb64018e1a010c4dfda975
sha512: 4d1aca14321b39b8c2d8aca14c57468ac78672ad169d12afc062d3314ffba7f82a656457478953d0e79f071ec0b9bd1fe980a7e83a1173c2297867446ed55562
ssdeep: 6144:Udl2axZwx/RIHjrP1e4pp+FUIj/tm3YujF4NffYY68oyEypDO+YpNNMdPIuigdeT:Udl2Ye4p1ZGW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 x54e6x54e6x54e6. All rights reserved.
Assembly Version: 8.4.6.6
FileVersion: 8.8.5.3
CompanyName: x513fx513fx827e
LegalTrademarks: x5a1cx9a6cx9a6c
Comments: x827ex827ex827e x827ex9a6cx9a6c
ProductName: x4e1dx827ex6bd4 x8d3cx8d3cx9a6c
ProductVersion: 8.4.6.6
FileDescription: x827ex827ex5409 x897fx897fx897f
OriginalFilename: x4e1dx827ex6bd4 x8d3cx8d3cx9a6c.exe
Translation: 0x0409 0x0514

MSIL/Kryptik.YKW also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44241861
FireEyeGeneric.mg.00ede4200f01ac7f
McAfeePWS-FCSS!00EDE4200F01
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056fa1a1 )
BitDefenderTrojan.GenericKD.44241861
K7GWTrojan ( 0056fa1a1 )
CrowdStrikewin/malicious_confidence_70% (W)
TrendMicroTROJ_GEN.R03FC0DJU20
BitDefenderThetaGen:NN.ZemsilF.34590.xm1@aGbTnbei
CyrenW32/MSIL_Kryptik.BXZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
AlibabaBackdoor:MSIL/Stealer.10a17920
Ad-AwareTrojan.GenericKD.44241861
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.xelrh
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.44241861 (B)
IkarusTrojan-Downloader.MSIL.Agent
AviraTR/Kryptik.xelrh
MicrosoftTrojan:MSIL/Stealer.RV!MTB
ArcabitTrojan.Generic.D2A313C5
AhnLab-V3Trojan/Win32.MSILKrypt.C4206356
ZoneAlarmHEUR:Backdoor.MSIL.Crysan.gen
GDataTrojan.GenericKD.44241861
CynetMalicious (score: 85)
ESET-NOD32a variant of MSIL/Kryptik.YKW
ALYacTrojan.GenericKD.44241861
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GZ.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03FC0DJU20
SentinelOneDFI – Malicious PE
FortinetMSIL/GenKryptik.EUVI!tr
AVGWin32:DangerousSig [Trj]
Cybereasonmalicious.d1938e
Paloaltogeneric.ml

How to remove MSIL/Kryptik.YKW?

MSIL/Kryptik.YKW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment