Malware

About “MSIL/Kryptik.ABLH” infection

Malware Removal

The MSIL/Kryptik.ABLH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ABLH virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ABLH?


File Info:

crc32: BE76F00F
md5: ac54156a7e43cf2ff559eccab719cd56
name: AC54156A7E43CF2FF559ECCAB719CD56.mlw
sha1: fac611cfa9eab717732bfe55c76a3c5e9ebbd6f9
sha256: 08c7314bebaa8766553ecedf92db572d0c434168dd9721967c9d11a48ca4e679
sha512: 3196c12a4cf06aeec21258a1cb257ee52355e5fc434d12cbdf39a8a42c6c1f275d1e89de58148e00a64814bc7b144fb56f144ada2688d78993728b562d8a8a52
ssdeep: 6144:SigI1J4iuRpiOIU+S+nRFfpXujHy1lSSz8twyM3Cuj7NkhJU1:D/4iuRpiTU+S+nRFfp+jdI2BM3C27gU1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright (C) 2014-2021
Assembly Version: 2.7.4.0
InternalName: IMG_003_166_372.exe
FileVersion: 2.7.4.0
CompanyName: Telegram FZ-LLC
LegalTrademarks:
Comments: Telegram Desktop
ProductName: Telegram Desktop
ProductVersion: 2.7.4.0
FileDescription: Telegram Desktop
OriginalFilename: IMG_003_166_372.exe

MSIL/Kryptik.ABLH also known as:

DrWebTrojan.PackedNET.835
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0057df2d1 )
Cybereasonmalicious.fa9eab
CyrenW32/MSIL_Agent.BCR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ABLH
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyUDS:DangerousObject.Multi.Generic
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.ac54156a7e43cf2f
SentinelOneStatic AI – Malicious PE
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!AC54156A7E43
MalwarebytesMachineLearning/Anomalous.95%
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.ABLH?

MSIL/Kryptik.ABLH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment