Malware

MSIL/Kryptik.ABOT removal instruction

Malware Removal

The MSIL/Kryptik.ABOT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ABOT virus can do?

  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ABOT?


File Info:

crc32: B4785004
md5: 0c1a9c5200dd6ad9e9adc3d2b23810fd
name: 0C1A9C5200DD6AD9E9ADC3D2B23810FD.mlw
sha1: 0396a39963056871619728cbbfd7f517a6247af6
sha256: 8487616e993913211f1c1d1888b24697f40132eed17e4f5ca2bf44b0edf036b7
sha512: dd1c6cfcfed510b780d10d2e8a66e72504e8dfe0deae0f9a6625c5880bfd6cb01ceaf1980e56ebfc578ddebba5483c85858078bd163586af45d91ca7f5f63bd6
ssdeep: 24576:5GgUrIQ95XZxWDXlRYa9BmLWBjqR9X0doH:5BQ95pyXlRX9QWZq7X0do
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Fix-KB xa92009-2016
Assembly Version: 1.0.7840.41912
InternalName: Thread.exe
FileVersion: 1.0.7840.41912
CompanyName: Fix-KB
LegalTrademarks:
Comments: A disk cleanup tool that throroughly scans your computer for unnecessary and invalid files no longer being used by the system.
ProductName: DriveTidy
ProductVersion: 1.0.7840.41912
FileDescription: DriveTidy
OriginalFilename: Thread.exe

MSIL/Kryptik.ABOT also known as:

K7AntiVirusTrojan ( 0057e52c1 )
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.526180
CylanceUnsafe
K7GWTrojan ( 0057e52c1 )
CyrenW32/Trojan.UIVF-0114
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ABOT
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderTrojan.GenericKD.37126025
MicroWorld-eScanTrojan.GenericKD.37126025
Ad-AwareTrojan.GenericKD.37126025
SophosMal/Generic-S
TrendMicroTrojanSpy.MSIL.NEGASTEAL.SMG
McAfee-GW-EditionRDN/Generic PWS.y
FireEyeTrojan.GenericKD.37126025
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.LokiBot.trask
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/AgentTesla!ml
ArcabitTrojan.Generic.D2367F89
AegisLabTrojan.MSIL.Androm.m!c
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataWin32.Trojan-Stealer.LokiBot.DCMQW3
AhnLab-V3Trojan/Win.NEGASTEAL.C4530419
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack.ADC.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.NEGASTEAL.SMG
IkarusTrojan-Spy.Win32.Lokibot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Androm!tr.bdr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove MSIL/Kryptik.ABOT?

MSIL/Kryptik.ABOT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment