Malware

MSIL/Kryptik.ABTL removal tips

Malware Removal

The MSIL/Kryptik.ABTL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.ABTL virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine MSIL/Kryptik.ABTL?


File Info:

crc32: 0B529F78
md5: baf4f3f3eeeec9b127321aff996b9ccf
name: BAF4F3F3EEEEC9B127321AFF996B9CCF.mlw
sha1: fb61f2442f18939e2e87577b6b06e44fe38f434c
sha256: 5a3fa956c8c6f4c56393717e712e7ce7a9876274388257361b4ce4196c190330
sha512: cb47e6e61440ec2e9aca271ed559aa3ab3e06676f8751c17517f473e4b60953de1316a8f4fa9abf4e96542f9e08f2c01357d46f2e94b1e944374f04788bfefc6
ssdeep: 12288:e7FCBbX5TyKe0vx53mIn1ABH52geDgXzAG/Xb08u6q:A0z9vrmI1ABZ2gSyzAG/Xxq
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017 - 2021
Assembly Version: 1.0.0.0
InternalName: OpFlags.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: HelloWorld
ProductVersion: 1.0.0.0
FileDescription: HelloWorld
OriginalFilename: OpFlags.exe

MSIL/Kryptik.ABTL also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.899
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.461543
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.42f189
CyrenW32/MSIL_Troj.BEP.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.ABTL
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyUDS:Trojan-PSW.MSIL.Agensla.gen
BitDefenderGen:Variant.Bulz.461543
MicroWorld-eScanGen:Variant.Bulz.461543
Ad-AwareGen:Variant.Bulz.461543
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34770.Qm0@auk2JFh
McAfee-GW-EditionAgentTesla-FDAH!BAF4F3F3EEEE
FireEyeGeneric.mg.baf4f3f3eeeec9b1
EmsisoftGen:Variant.Bulz.461543 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla.CM!MTB
ArcabitTrojan.Bulz.D70AE7
GDataGen:Variant.Bulz.461543
McAfeeAgentTesla-FDAH!BAF4F3F3EEEE
MAXmalware (ai score=85)
MalwarebytesMalware.AI.2110045223
IkarusTrojan-Spy.FormBook
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.DLO!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwMAS5sA

How to remove MSIL/Kryptik.ABTL?

MSIL/Kryptik.ABTL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment