Malware

How to remove “MSIL/Kryptik.YOC”?

Malware Removal

The MSIL/Kryptik.YOC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YOC virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.YOC?


File Info:

crc32: 5A0C4BD9
md5: 96697eae976962a7ca0a3fb8f9befa13
name: 96697EAE976962A7CA0A3FB8F9BEFA13.mlw
sha1: 5b1e2374d9b454b504584c89f599752adde69e91
sha256: 82c53ee74253581efe369c99373d6c978b3b9b799eb04de6c4eb59d2825e8ee2
sha512: 9c9be932b4a93a432fb1ed8034bbf900f913672737136be13fb061f975f75e15b12c6e62972a59523f5e2b7ba6313e849a1962902f763bdb1eff1fa85934b8e4
ssdeep: 12288:V9bscvXsmIkiWA1d3aZRJJ1bGc11PDBrwJQohfuUeUCmF:NvXgkiWA1xa5ScDPkhL
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Schatz Grt 2020
Assembly Version: 31.4.0.0
InternalName: Qft6.exe
FileVersion: 31.6.4.0
CompanyName: Schatz ltd
LegalTrademarks: Tag zu Tag
Comments: Ich mxf6chte den Rest meines Lebens mit Dir verbringen
ProductName: Willst du
ProductVersion: 31.6.4.0
FileDescription: Willst du
OriginalFilename: Qft6.exe

MSIL/Kryptik.YOC also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71297
FireEyeTrojan.GenericKDZ.71297
ALYacTrojan.GenericKDZ.71297
CylanceUnsafe
BitDefenderTrojan.GenericKDZ.71297
CyrenW32/MSIL_Troj.ZR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
RisingTrojan.Kryptik!8.8 (TFE:C:MP1IQZscKBU)
Ad-AwareTrojan.GenericKDZ.71297
SophosTroj/Kryptik-NR
F-SecureTrojan.TR/AD.Swotter.nxnuq
DrWebTrojan.Inject4.4624
VIPRETrojan.Win32.Generic!BT
InvinceaTroj/Kryptik-NR
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
MaxSecureTrojan.Malware.74499699.susgen
EmsisoftTrojan.GenericKDZ.71297 (B)
IkarusTrojan.MSIL.Inject
AviraTR/AD.Swotter.nxnuq
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Generic.D11681
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKDZ.71297
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AgentTesla.R355328
McAfeePWS-FCSU!96697EAE9769
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.YOC
YandexTrojan.AvsArher.bTJEKx
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_64%
FortinetMSIL/GenKryptik.EUOZ!tr
BitDefenderThetaGen:NN.ZemsilF.34590.4m0@a8UJRsj
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.4d9b45
Qihoo-360HEUR/QVM03.0.38DF.Malware.Gen

How to remove MSIL/Kryptik.YOC?

MSIL/Kryptik.YOC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment