Malware

MSIL/Kryptik.YYD information

Malware Removal

The MSIL/Kryptik.YYD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.YYD virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine MSIL/Kryptik.YYD?


File Info:

name: F4FA6D2A373A8EBD8B21.mlw
path: /opt/CAPEv2/storage/binaries/1fae2487974c00b95bc5a8fc4a07850b1fbe0a1922778994c08eeecddb21930a
crc32: 06B4ACA7
md5: f4fa6d2a373a8ebd8b219e84a95ef25b
sha1: 5812ad99e07e0b95a76616e103702d367cca669d
sha256: 1fae2487974c00b95bc5a8fc4a07850b1fbe0a1922778994c08eeecddb21930a
sha512: 0236221a98de06249d746b1b187e2b8404b76e1dc170004169bea058b572c4b5ed085883b4f76cf2d66502a507cc60199505b3f9c0e3f2ded4d43c3d10368be1
ssdeep: 3072:GoGBCbywMNEu5s0QzZaSWJg2G4eieaDhU4q+vXfE783:GhBCbyw3eof9uvo8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134C37C3EAAA42A27B77FD17546834055F4BC90EB36315CD782C76A88750D9023EEE36C
sha3_384: 0ff734e1a16b2117db2e0438f7f0c0a8db9d8774891fe2c78c0f5afb2082df7ff0608f971f4f2041f47866bfed526454
ep_bytes: ff250020400000000000000000000000
timestamp: 2068-02-17 15:40:05

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: clearpo
FileVersion: 1.0.0.0
InternalName: clearpo.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: clearpo.exe
ProductName: clearpo
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.YYD also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Johnnie.364377
FireEyeGeneric.mg.f4fa6d2a373a8ebd
CAT-QuickHealTrojan.Agenttesla
McAfeePWS-FCUA!F4FA6D2A373A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005744231 )
K7GWTrojan ( 005744231 )
Cybereasonmalicious.a373a8
BitDefenderThetaGen:NN.ZemsilF.34742.hm0@aCODEej
CyrenW32/MSIL_Kryptik.AWF.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.YYD
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Johnnie.364377
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Johnnie.364377
SophosGeneric ML PUA (PUA)
EmsisoftGen:Variant.Johnnie.364377 (B)
IkarusTrojan.MSIL.Krypt
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
MicrosoftTrojan:MSIL/AgentTesla.BYY!MTB
GDataGen:Variant.Johnnie.364377
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4262899
Acronissuspicious
ALYacGen:Variant.Johnnie.364377
MalwarebytesBladabindi.Backdoor.Njrat.DDS
APEXMalicious
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:KXJyOep0Ok8Agpe91X+V1Q)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.YWW!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Kryptik.YYD?

MSIL/Kryptik.YYD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment