Malware

MSIL/Kryptik.YOU removal guide

Malware Removal

The MSIL/Kryptik.YOU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YOU virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.YOU?


File Info:

crc32: 15C0029D
md5: b9fbeb9df74efd48f3f065b6748a3cca
name: B9FBEB9DF74EFD48F3F065B6748A3CCA.mlw
sha1: bfadd8dd6d23b9cb16d252a5063a81340c485b57
sha256: ca635625db0e17196413bedd85233c035afdf7088cfbe6c0d43967f235db3070
sha512: 7c435e3426cbfa45e03cb84e6204784de123fc0054944bdba7a29a1538cf9d295e12e2c76178353858da8c5788dda008262b7609b50f6153172855f794c91fdb
ssdeep: 6144:02hrBerMB1QlU36xFMH70+unPRPFoDYsGmClviPDTSG9VTq16zK+vGEAmg+G8:08rBerMIlU3UYQxPoDYsGmuireG721L
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 2019-2020 Adobe. All rights reserved.
Assembly Version: 5.3.1.470
InternalName: drc9.exe
FileVersion: 5.3.1.470
CompanyName: Adobe Inc.
Comments: Creative Cloud Desktop
ProductName: Creative Cloud Desktop
ProductVersion: 5.3.1.470
FileDescription: Creative Cloud Desktop
OriginalFilename: drc9.exe

MSIL/Kryptik.YOU also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35167284
FireEyeGeneric.mg.b9fbeb9df74efd48
McAfeePWS-FCSX!B9FBEB9DF74E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0057287e1 )
BitDefenderTrojan.GenericKD.35167284
K7GWTrojan ( 0057287e1 )
Cybereasonmalicious.d6d23b
InvinceaMal/Generic-S
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-PSW.MSIL.Stelega.gen
AlibabaTrojanPSW:MSIL/Kryptik.66a17d55
TencentMsil.Trojan-qqpass.Qqrob.Pjnn
Ad-AwareTrojan.GenericKD.35167284
SophosMal/Generic-S
F-SecureTrojan.TR/AD.AgentTesla.taemi
DrWebBackDoor.SpyBotNET.25
TrendMicroTROJ_GEN.R023C0PKC20
McAfee-GW-EditionPWS-FCSX!B9FBEB9DF74E
EmsisoftTrojan.GenericKD.35167284 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.AgentTesla.taemi
MicrosoftTrojan:Win32/Ymacco.AAA8
ArcabitTrojan.Generic.D2189C34
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stelega.gen
GDataTrojan.GenericKD.35167284
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZemsilF.34634.wm0@aOk8ikg
MAXmalware (ai score=83)
MalwarebytesTrojan.MZCrypt.MSIL.Generic
PandaTrj/GdSda.A
ZonerTrojan.Win32.98096
ESET-NOD32a variant of MSIL/Kryptik.YOU
TrendMicro-HouseCallTROJ_GEN.R023C0PKC20
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_96%
FortinetMSIL/GenKryptik.EVWY!tr
MaxSecureTrojan.Malware.74811258.susgen
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/HEUR/QVM03.0.2CA2.Malware.Gen

How to remove MSIL/Kryptik.YOU?

MSIL/Kryptik.YOU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment