Malware

MSIL/Kryptik.AFSM removal guide

Malware Removal

The MSIL/Kryptik.AFSM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AFSM virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.AFSM?


File Info:

name: 177C23835441B683AF19.mlw
path: /opt/CAPEv2/storage/binaries/195c08e37de18c2ad655cf211056abb74181d330099c085b6c5cb835f8e89a26
crc32: B828C56E
md5: 177c23835441b683af19a4cb12d8a281
sha1: 2bcb19d398b49e91419b792d94e22682b129299a
sha256: 195c08e37de18c2ad655cf211056abb74181d330099c085b6c5cb835f8e89a26
sha512: a4467b92e97044533063549f8e55dc65e30c316d9425ae883e22d4882f6207913848c8147ef6aab2fc412c8b87e238e3014efafa381a963034f43087c087c127
ssdeep: 12288:Yp8FJwdzbJnDQL/Ra2IXxbCQ/DjhKHdz7JXwSEHpgF6BgJJiPEa4lml:68/wdzFnDERmFJ/DE9z7fEgFPJU4o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14215BF6337600AA5C13DB7FE2616467363B2F0C76C14CA4B9D86E2DA7B227518E709C7
sha3_384: fec8ddcaf2f7a1fab078753753fcb3527648f027d1d29bb261ad000c9765e977bbcf5ee07dbcfa7138457faa1958ddb1
ep_bytes: ff250020400000000000000000000000
timestamp: 1992-01-10 06:50:17

Version Info:

CompanyName: Adersoft
FileDescription: HTML Applications Engine
FileVersion: 9.2.13.1
InternalName: html.exe
LegalCopyright: Copyright Adersoft (C) 2001-2020
OriginalFilename: html.exe
ProductName: VbsEdit
ProductVersion: 9.2.13.1
Translation: 0x0409 0x04b0

MSIL/Kryptik.AFSM also known as:

BkavW32.AIDetectNet.01
LionicRiskware.Win32.Pretoria.1!c
MicroWorld-eScanGen:Heur.MSIL.Pretoria.1
FireEyeGeneric.mg.177c23835441b683
McAfeeRDN/Generic.dx
CylanceUnsafe
VIPREGen:Heur.MSIL.Pretoria.1
SangforSuspicious.Win32.Save.a
AlibabaRansom:MSIL/Blocker.7d536796
Cybereasonmalicious.35441b
SymantecPacked.Generic.619
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AFSM
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderGen:Heur.MSIL.Pretoria.1
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan.Blocker.Dygy
Ad-AwareGen:Heur.MSIL.Pretoria.1
EmsisoftGen:Heur.MSIL.Pretoria.1 (B)
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosGeneric PUA CL (PUA)
IkarusGen.MSIL.Pretoria
GDataGen:Heur.MSIL.Pretoria.1
Antiy-AVLTrojan/Generic.ASMalwS.720E
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.MSIL.Pretoria.1
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Pretoria.C5206017
Acronissuspicious
ALYacGen:Heur.MSIL.Pretoria.1
MAXmalware (ai score=85)
TrendMicro-HouseCallTROJ_GEN.R002H09GE22
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL:3HHJ2qOshXXoGmvk8uNYAA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34786.1m0@aq7l!0f
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MSIL/Kryptik.AFSM?

MSIL/Kryptik.AFSM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment