Malware

MSIL/Kryptik.ABCB (file analysis)

Malware Removal

The MSIL/Kryptik.ABCB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ABCB virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ABCB?


File Info:

crc32: E4FF23EF
md5: 96835315e4668175770a668db2255844
name: 96835315E4668175770A668DB2255844.mlw
sha1: 87c2444092782d9ddfa5701c06d499187ba1b2f0
sha256: 6168a4dd7705ba99b43d7f9f1a8d033a8028effd22d474bb6930b333dd232cc3
sha512: ee22639721607b40630e76d5c17ad0fc01ec2c38370af3a78a4052377bf6ba5a4fec3e8cf1ff8624688db8bce57f566449101dbb493763d7bf74ca5f5f022b41
ssdeep: 12288:zxDtAMOmmF7FVl+bBylvaqCg8SdHLdmQAJ6nSrXtDA:c7DMBylZXdBmQAo2DA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (C) 2016-2020
Assembly Version: 1.3.5.0
InternalName: 5wMO.exe
FileVersion: 1.3.5.0
CompanyName: Bogdan Sharkov
LegalTrademarks:
Comments:
ProductName: Clownfish Voice Changer
ProductVersion: 1.3.5.0
FileDescription: Clownfish Voice Changer
OriginalFilename: 5wMO.exe

MSIL/Kryptik.ABCB also known as:

K7AntiVirusTrojan ( 0057cfdd1 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.761
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.MSIL
ALYacTrojan.GenericKD.46356989
CylanceUnsafe
SangforTrojan.MSIL.Taskun.gen
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/starter.ali1000139
K7GWTrojan ( 0057cfdd1 )
Cybereasonmalicious.092782
CyrenW32/MSIL_Kryptik.EIS.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ABCB
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Taskun.gen
BitDefenderTrojan.GenericKD.46356989
MicroWorld-eScanTrojan.GenericKD.46356989
Ad-AwareTrojan.GenericKD.46356989
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.oikcr@0
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DER21
McAfee-GW-EditionBehavesLike.Win32.Fareit.hc
FireEyeGeneric.mg.96835315e4668175
EmsisoftTrojan.GenericKD.46356989 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.eqal
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/Stealer.MS!MTB
ArcabitTrojan.Generic.D2C359FD
GDataTrojan.GenericKD.46356989
AhnLab-V3Trojan/Win.Generic.C4490978
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.PNG.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DER21
RisingStealer.Agent!8.C2 (CLOUD)
YandexTrojan.AvsArher.bTJEKx
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.AAYL!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.ABCB?

MSIL/Kryptik.ABCB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment