Malware

MSIL/Kryptik.ABTD removal tips

Malware Removal

The MSIL/Kryptik.ABTD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ABTD virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine MSIL/Kryptik.ABTD?


File Info:

crc32: 884372DF
md5: 3492b1c33fcaa892615aa673b9283014
name: 3492B1C33FCAA892615AA673B9283014.mlw
sha1: b13dde42895155a85837287c2b7eaf371af94752
sha256: 531686f56257eafa0da5908fa50d5ef2ef51efee156c1185c212ed0958ee5b59
sha512: d0c1c0e91189ccd0e74306fccdf7a9c4d816fe1eb3a25c8cabf799dfd723213ccd05e56a7f6cc6aae6dc39c90f7e49e35be7ee6ffa69e047de032a0ce87b043c
ssdeep: 12288:yDUuZX+iDsJRCb1cQ9Ylue3m7ULjUlNzYhxQdVjCk2GEXJ+Ult:yDP8O1jCH3zjkWhadHI5j
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: MzgG.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: PharmaPlus
ProductVersion: 1.0.0.0
FileDescription: PharmaPlus
OriginalFilename: MzgG.exe

MSIL/Kryptik.ABTD also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.15741
ALYacSpyware.AgentTesla
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/Agensla.2d8ba726
K7GWTrojan ( 0057eac81 )
CyrenW32/MSIL_Troj.BDX.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ABTD
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderTrojan.GenericKDZ.76139
MicroWorld-eScanTrojan.GenericKDZ.76139
Ad-AwareTrojan.GenericKDZ.76139
ComodoMalware@#c9cyir6tndan
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-FCZI!3492B1C33FCA
FireEyeGeneric.mg.3492b1c33fcaa892
EmsisoftMalCert.A (A)
WebrootW32.Trojan.Gen
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.STA
ArcabitTrojan.Generic.D1296B
AegisLabTrojan.MSIL.Noon.l!c
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataTrojan.GenericKDZ.76139
AhnLab-V3Malware/Win.Generic.C4537648
McAfeePWS-FCZI!3492B1C33FCA
MAXmalware (ai score=87)
VBA32TScope.Trojan.MSIL
MalwarebytesSpyware.Agent
PandaTrj/CI.A
IkarusTrojan.Inject
FortinetMSIL/Kryptik.ABQV!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.AgentTesla.HgIASXYA

How to remove MSIL/Kryptik.ABTD?

MSIL/Kryptik.ABTD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment