Malware

MSIL/Kryptik.AAHQ removal

Malware Removal

The MSIL/Kryptik.AAHQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AAHQ virus can do?

  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine MSIL/Kryptik.AAHQ?


File Info:

crc32: 5EE3EBC9
md5: bfca5d2ddd8840dc1f6c49309bbe1924
name: BFCA5D2DDD8840DC1F6C49309BBE1924.mlw
sha1: b0f0462dfa8fd68617a7e458f9f24586177b3ed2
sha256: ef1bc7566ce113d6af42b9eecc63f0b69b3eeebcc2896d63bf948be6c295dc3a
sha512: 8c54c8a7a37c637dc6bde8603433b5da536a796aaccc19e22c1e781a9907e6d891b49bbf051837719ca582f3f1e154851ab82d1a53eb47ab2a882caf3c14dda7
ssdeep: 24576:1Oio4e8+h7g9NrNINlRnsFa3SXZ+87xrg:u4igMOa38Zbl0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright ClientForQfmsAuthBCencticrJationMembershipProvider 2005
Assembly Version: 615.617.32.179
InternalName: ServiceDescriptionFormatExtension.exe
FileVersion: 204.182.139.377
CompanyName: ClientForQfmsAuthBCencticrJationMembershipProvider
LegalTrademarks:
Comments: PorofjcessGvWindwowStyle
ProductName: RegistkeTrAssembKly
ProductVersion: 204.182.139.377
FileDescription: SLfcripjDtRSeferJenceEventArgs
OriginalFilename: ServiceDescriptionFormatExtension.exe

MSIL/Kryptik.AAHQ also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.19278
CynetMalicious (score: 99)
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.adcb007c
K7GWTrojan ( 0057a57b1 )
Cybereasonmalicious.dfa8fd
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Kryptik.AAHQ
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-PSW.MSIL.Coins.gen
BitDefenderTrojan.GenericKD.36688148
MicroWorld-eScanTrojan.GenericKD.36688148
Ad-AwareTrojan.GenericKD.36688148
SophosGeneric PUA LA (PUA)
ComodoMalware@#1l8u05miif1j9
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.36688148
EmsisoftTrojan.GenericKD.36688148 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.vmguc
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Generic.D22FD114
GDataTrojan.GenericKD.36688148
McAfeeArtemis!BFCA5D2DDD88
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.AAHQ!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Kryptik.HgIASSkA

How to remove MSIL/Kryptik.AAHQ?

MSIL/Kryptik.AAHQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment