Malware

MSIL/Kryptik.ABHQ removal guide

Malware Removal

The MSIL/Kryptik.ABHQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ABHQ virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ABHQ?


File Info:

crc32: F2A83378
md5: fcaf78480982a67d36e9d3ce6739e9a6
name: FCAF78480982A67D36E9D3CE6739E9A6.mlw
sha1: a5935fcfb5e9e17b62b3507b3606b88e3c09e2ef
sha256: 51fe2c51a6740eaeb26da0aa3524654d0e50d2a1217a6e00679e8fe6022603ed
sha512: 4b7839df9146db5e0e56bfa1712ec9f95395e8d574fee10b14935732aad7ef5338d7693af88c8b33737a51f660be9e6b251b5926646543434d2862372dc78e7f
ssdeep: 12288:YvMsO5wa9sOkRAbWlhJP652umOSiAwN2iudxabb:7bb
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: All Rights Reserved
Assembly Version: 5.378.776.654
InternalName: xcad2xca9fxcaa0xcad0xcac3xcaa2xca9fxcab2xcab0xcab1xcaa6xca9excaa4xcac0xcaa4xcab5xcaa7xcaa4xcae7xcaa2xcabcxca9fxcad0xcaa6xcab2xcaa1xcaa6xcaa1xcad2xcabcxcac4xca9excaa3xcad1xcaa4xcabfxcab9xcad4.exe
FileVersion: 5.378.776.654
CompanyName: xcad2xca9fxcaa0xcad0xcac3xcaa2xca9fxcab2xcab0xcab1xcaa6xca9excaa4xcac0xcaa4xcab5xcaa7xcaa4xcae7xcaa2xcabcxca9fxcad0xcaa6xcab2xcaa1xcaa6xcaa1xcad2xcabcxcac4xca9excaa3xcad1xcaa4xcabfxcab9xcad4 Inc.
LegalTrademarks: xcad2xca9fxcaa0xcad0xcac3xcaa2xca9fxcab2xcab0xcab1xcaa6xca9excaa4xcac0xcaa4xcab5xcaa7xcaa4xcae7xcaa2xcabcxca9fxcad0xcaa6xcab2xcaa1xcaa6xcaa1xcad2xcabcxcac4xca9excaa3xcad1xcaa4xcabfxcab9xcad4
Comments: xcad2xca9fxcaa0xcad0xcac3xcaa2xca9fxcab2xcab0xcab1xcaa6xca9excaa4xcac0xcaa4xcab5xcaa7xcaa4xcae7xcaa2xcabcxca9fxcad0xcaa6xcab2xcaa1xcaa6xcaa1xcad2xcabcxcac4xca9excaa3xcad1xcaa4xcabfxcab9xcad4
ProductName: xcad2xca9fxcaa0xcad0xcac3xcaa2xca9fxcab2xcab0xcab1xcaa6xca9excaa4xcac0xcaa4xcab5xcaa7xcaa4xcae7xcaa2xcabcxca9fxcad0xcaa6xcab2xcaa1xcaa6xcaa1xcad2xcabcxcac4xca9excaa3xcad1xcaa4xcabfxcab9xcad4
ProductVersion: 5.378.776.654
FileDescription: xcad2xca9fxcaa0xcad0xcac3xcaa2xca9fxcab2xcab0xcab1xcaa6xca9excaa4xcac0xcaa4xcab5xcaa7xcaa4xcae7xcaa2xcabcxca9fxcad0xcaa6xcab2xcaa1xcaa6xcaa1xcad2xcabcxcac4xca9excaa3xcad1xcaa4xcabfxcab9xcad4
OriginalFilename: xcad2xca9fxcaa0xcad0xcac3xcaa2xca9fxcab2xcab0xcab1xcaa6xca9excaa4xcac0xcaa4xcab5xcaa7xcaa4xcae7xcaa2xcabcxca9fxcad0xcaa6xcab2xcaa1xcaa6xcaa1xcad2xcabcxcac4xca9excaa3xcad1xcaa4xcabfxcab9xcad4.exe
Translation: 0x0000 0x0514

MSIL/Kryptik.ABHQ also known as:

K7AntiVirusTrojan ( 0057da801 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46440779
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Kryptik.ali2000016
K7GWTrojan ( 0057da801 )
Cybereasonmalicious.fb5e9e
CyrenW32/MSIL_Agent.BZZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ABHQ
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
BitDefenderTrojan.GenericKD.46440779
MicroWorld-eScanTrojan.GenericKD.46440779
Ad-AwareTrojan.GenericKD.46440779
SophosGeneric PUA KF (PUA)
F-SecureTrojan.TR/Kryptik.fgsta
BitDefenderThetaGen:NN.ZemsilF.34722.Dm1@aynAuimi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.fcaf78480982a67d
EmsisoftTrojan.GenericKD.46440779 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.bqgk
AviraTR/Kryptik.fgsta
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D2C4A14B
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmHEUR:Trojan-PSW.MSIL.Reline.gen
GDataTrojan.GenericKD.46440779
AhnLab-V3Trojan/Win.Generic.C4520814
McAfeeArtemis!FCAF78480982
MAXmalware (ai score=80)
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/GdSda.A
IkarusTrojan-Downloader.MSIL.Agent
FortinetMSIL/Kryptik.ABHQ!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.ABHQ?

MSIL/Kryptik.ABHQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment