Malware

What is “VirTool:MSIL/CryptInject.YO!MTB”?

Malware Removal

The VirTool:MSIL/CryptInject.YO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:MSIL/CryptInject.YO!MTB virus can do?

  • Authenticode signature is invalid

How to determine VirTool:MSIL/CryptInject.YO!MTB?


File Info:

name: F5396F28A93F43F2BE91.mlw
path: /opt/CAPEv2/storage/binaries/2d1a9e372064de5c2e83732333ef59a3e7071a4267bdfb98201f9e3d43767016
crc32: 850AA494
md5: f5396f28a93f43f2be91e7ba065d0345
sha1: 248ef18a05bebf61d3790b4b5a03a0cddd3b8640
sha256: 2d1a9e372064de5c2e83732333ef59a3e7071a4267bdfb98201f9e3d43767016
sha512: a1fce9e749381457c859e224189a422a26c3300be4cbb85aa5ba586255a01a8378010ddecbe40106eed3b953153613e09a3b99ef1c3621de83f3ad9af6d82cc8
ssdeep: 1536:wd4viZUP2zcEHKUa0PCekugOKD7ylH8lZRlatjXKlyXXa76HLyNIra0mXpleo5Ok:saAWyNOojXK+MNSiXvnn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182A37C2337E45B58E2BD67B20523A64052F5F51BD636E36C3D4C918C893ABC2D2927E3
sha3_384: 166a4fa155995c3c4f8ed8d828ed99efa59309f9a9ed38d107d8d59c16477b900192ba5ff0558b7df6cc1a060263cf06
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-23 13:30:12

Version Info:

Translation: 0x0000 0x04b0
Comments: ӔЖ難おкяЗみかЌлзгひа与へ難аӧへ亊く亊ҍへлҍФл
CompanyName: 五рめきき四予きзḆふлӔЉ難оЊうまг予лтб五あЗсқк
FileDescription: мϚ争うьҶоддҍзлへЗо亊иώḒЊ六ӧみ亊うҍьЗдけ
FileVersion: 5.6.7.8
InternalName: Server.exe
LegalCopyright: Copyright © мϚ争うьҶоддҍзлへЗо亊иώḒЊ六ӧみ亊うҍьЗдけ 2014
LegalTrademarks:
OriginalFilename: Server.exe
ProductName: めは五дальятϐзあа革ъ亊ЀӧрҶЉо骨いώл六тえ争
ProductVersion: 5.6.7.8
Assembly Version: 1.2.3.4

VirTool:MSIL/CryptInject.YO!MTB also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader12.28002
FireEyeGeneric.mg.f5396f28a93f43f2
McAfeeArtemis!F5396F28A93F
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZemsilF.34294.gm0@aeuhx9l
ClamAVWin.Packed.Generic-9865070-0
RisingTrojan.Generic@ML.81 (RDML:gSNANe3yCG77tiZUIhc6Eg)
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Malicious PE
IkarusTrojan.MSIL.Injector
AviraTR/AD.Bladabindi.anpby
MicrosoftVirTool:MSIL/CryptInject.YO!MTB
GDataWin32.Trojan.PSE.W9N9ZF
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C4265994
APEXMalicious
AVGWin32:InjectorX-gen [Trj]
Cybereasonmalicious.a05beb
AvastWin32:InjectorX-gen [Trj]

How to remove VirTool:MSIL/CryptInject.YO!MTB?

VirTool:MSIL/CryptInject.YO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment