Trojan

About “Trojan.MSIL.Crypt.htof” infection

Malware Removal

The Trojan.MSIL.Crypt.htof is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Crypt.htof virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan.MSIL.Crypt.htof?


File Info:

crc32: 9196D43F
md5: 970247901268bd976aa5eb37d8e703ad
name: 970247901268BD976AA5EB37D8E703AD.mlw
sha1: f40093b791f05f74db82b6050521b5b10d081580
sha256: d5956571b9e9bc5c925d5b26a0bd0771c636bff202c0adb7d1d9ad6efe487bae
sha512: eb7facd2bf4373d847caea0b277e7c973ac9f79bb954cecf247c4f19f63be94b43feff5e5447f900b513ccfc04c37beeff99405776baf8257ee11c5a9e37c13f
ssdeep: 1536:aJ+Q4zxApEVH7fj0FpyvG9hApGL8qNnEj:aezxz9LjepQ/GL8qNnEj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Nexus Corporation
InternalName: Illegals5
FileVersion: 4.00
CompanyName: Nexus Corporation
LegalTrademarks: Nexus Corporation
Comments: Nexus Corporation
ProductName: jesus
ProductVersion: 4.00
OriginalFilename: Illegals5.exe

Trojan.MSIL.Crypt.htof also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0057c9e21 )
Elasticmalicious (high confidence)
McAfeeArtemis!970247901268
CylanceUnsafe
SangforTrojan.Win32.VBInject.PKI
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/VBInject.47a9c027
K7GWTrojan ( 0057c9e21 )
CyrenW32/VB.TE.gen!Eldorado
ESET-NOD32a variant of Win32/Injector.EPJA
APEXMalicious
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.MSIL.Crypt.htof
BitDefenderTrojan.GenericKD.36928678
MicroWorld-eScanTrojan.GenericKD.36928678
Ad-AwareTrojan.GenericKD.36928678
BitDefenderThetaGen:NN.ZevbaF.34690.gm1@a07YJfmi
TrendMicroTROJ_GEN.R002C0DEJ21
McAfee-GW-EditionPWS-FCYQ!970247901268
FireEyeGeneric.mg.970247901268bd97
EmsisoftTrojan.GenericKD.36928678 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_94%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/VBInject.PKI!MTB
AegisLabTrojan.Win32.Blocker.j!c
GDataWin32.Trojan.Agent.1VHKIP
MalwarebytesMalware.AI.644347329
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DEJ21
RisingTrojan.Injector!8.C4 (CLOUD)
FortinetW32/Kryptik.EPJA!tr
AVGWin32:DangerousSig [Trj]

How to remove Trojan.MSIL.Crypt.htof?

Trojan.MSIL.Crypt.htof removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment